Managed XDR

c-windows-installer-588262.msi (Grandoreiro) — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
c-windows-installer-588262.msi
Тип файла
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Code page: 1252, Revision Number: {F052A23C-4A43-4606-9CB4-83AC61C1221B}, Number of Words: 10, Subject: Installer, Author: Installer, Name of Creating Application: Installer 64247, Template: ;1033, Title: Installation Database, Keywords: Installer, MSI, Database, Security: 0, Create Time/Date: Tue Feb 4 21:18:35 2025, Last Saved Time/Date: Tue Feb 4 21:18:35 2025, Last Printed: Tue Feb 4 21:18:35 2025, Number of Pages: 200
Размер файла
14.2 MB
Первое обнаружение
Последнее обнаружение

Окружение

w10/x86 en

Хеши

SHA1
ebfd7ef786b252696480bcf457f72e9636000b53
SHA256
3190bb453b18829820e4b806b255eab40fd8a60c7332fe83058f9c8afd5e882c
MD5
5da32442c003c9eaaa431c64a0f2b486

Вредоносное ПО

  • Grandoreiro

Сигнатуры

Persistence

T1574 dropper_dll: Creates DLL, which is then loaded into the process

Privilege Escalation

T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497 evasion_diskenum: Sandbox evasion using enumeration of partitions
T1497.001 antivm_queries_computername: Retrieves the computer name
T1480 system_default_lang_id_present: Checks the system language
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1574 dropper_dll: Creates DLL, which is then loaded into the process

Discovery

T1497 evasion_diskenum: Sandbox evasion using enumeration of partitions
T1497.001 antivm_queries_computername: Retrieves the computer name

Command and Control

T1071.001 network_http: Performs HTTP requests
T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp
T1071.001 wininet_openurl: Performs HTTP/HTTPS-requests using InternetOpenUrl

Other

yara_rules: Static rules
ce_info: Grandoreiro Configuration Data found
grandoreiro_loader_behavior: Exhibits behavior characteristics of Grandoreiro loader
creates_exe: Creates executable files in the file system
suspicious_process_network: Unusual process network activity detected
no_graphical_activity: No graphic activity
create_rpc_bindings: Creates RPC connection
creates_suspended_process: Creates suspended process
msi_has_custom_action: MSI file contains custom action
test_check_service: Starts services
checktokenmembership: Checks user token with CheckTokenMembership call
suricata_alert: Malicious traffic detected

Похожие отчёты