Managed XDR

c-users-user-appdata-l...610a379b92471891a04d9d (Conti) — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
c-users-user-appdata-local-temp-ymnkxc2u.nkl-exe.ransomware.conti-c2-1b-56-c21b56c945941a2aa5d3201...8bb9aa1772d610a379b92471891a04d9d-c21b56c945941a2aa5d32013b5af8908bb9aa1772d610a379b92471891a04d9d
Тип файла
PE32 executable (GUI) Intel 80386, for MS Windows
Размер файла
185.5 KB
Первое обнаружение
Последнее обнаружение

Окружение

w10/x64 en

Хеши

SHA1
35285c99c8a59fe1b5c62525ba1bd06cbcde5efe
SHA256
c21b56c945941a2aa5d32013b5af8908bb9aa1772d610a379b92471891a04d9d
MD5
32d7a44028555ef3d52397e12b7de576

Вредоносное ПО

  • Conti

Сигнатуры

Execution

T1047 has_wmi: Executes one or several WMI requests

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1057 process_interest: Enumerates processes
T1083 crawls_directories: Opens a huge number of directories all over disk C: (possibly, searches for sensitive data)
T1518 locates_browser: Attempts to identify where browsers are installed
T1016 get_hostname: Attempts to get hostname

Impact

T1486 modifies_files: Cryptolocker indicators detected (renamed 100 or more files)
T1486 modifies_files2: Cryptolocker indicators detected (100 or more files are modified)
T1486 ransomware_files: Ransomware indicators detected Conti (creates keys and the instruction on how to unlock the files)
T1486 ransomware_files_2: Ransomware(s) Conti indicators detected (creates keys and the instruction on how to unlock the files)

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
create_rpc_bindings: Creates RPC connection
creates_in_programdata: Creates files in the ProgramData directory

Похожие отчёты