Managed XDR

2.zip (PlugX) — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
2.zip
Тип файла
Zip archive data, at least v2.0 to extract
Размер файла
370.4 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x64 en

Хеши

SHA1
7a509cb041056f7567127f0c28f22815d149ea91
SHA256
66b861a88dfb8c4b6d764f7e2aef1c550b24dd7d938610f362a0ab86665ec7a1
MD5
7dec7cdb4f3d5f9df8af8ad53d745846

Вредоносное ПО

  • PlugX

Сигнатуры

Execution

T1569.002 persistence_service: Starts newly created service
T1559.001 com_exec: Execution of Win32_Process.Create COM Method

Persistence

T1543.003 creates_service: Creates a service, that will start automatically
T1574 dropper_dll: Creates DLL, which is then loaded into the process

Privilege Escalation

T1543.003 creates_service: Creates a service, that will start automatically
T1055 injection_thread: Code injection to a remote process using CreateRemoteThread or NtQueueApcThread
T1055.012 injection_runpe: Injects code into another process
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1055 injection_thread: Code injection to a remote process using CreateRemoteThread or NtQueueApcThread
T1055.012 injection_runpe: Injects code into another process
T1070.004 deletes_self: Moves to different location or removes the original executable file
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1564.001 stealth_file: Creates hidden or system files
T1027.002 packer_vmprotect: Executable file is likely compressed using VMProtect
T1497 debugs_self: Creates a process and debugs it
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1497.001 antivm_queries_computername: Retrieves the computer name
T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Credential Access

T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files
T1056.001 infostealer_keylogger: Keylogger (intercepts keystrokes)

Discovery

T1497 debugs_self: Creates a process and debugs it
T1518.001 av_detect_china_key: Checks for registry key typical for Chinese AV software
T1497.001 antivm_queries_computername: Retrieves the computer name
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1082 reads_csrss: Attempts to read csrss.exe memory

Collection

T1115 checks_clipboard: Monitors clipboard data
T1056.001 infostealer_keylogger: Keylogger (intercepts keystrokes)

Command and Control

T1071.001 wininet_openurl: Performs HTTP/HTTPS-requests using InternetOpenUrl

Other

yara_rules: Static rules
suricata_alert: Malicious traffic detected
suspicious_process: Spawns a suspicious process
creates_exe: Creates executable files in the file system
dns_without_resolve: DNS query without a response
dead_host: Connects to IP addresses that do not respond to requests
executes_dropped_exe: Executes dropped exe files
no_graphical_activity: No graphic activity
valid_authenticode: The digital signature has been verified
create_rpc_bindings: Creates RPC connection
has_pdb: This executable file has a PDB path
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object
creates_in_programdata: Creates files in the ProgramData directory
test_check_service: Starts services
pe_overlay: PE file contains overlay

Похожие отчёты