Windows
Analysis Report
PA.bin.exe
Overview
General Information
Detection
Score: | 56 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Contains functionality for read data from the clipboard
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to call native functions
Contains functionality to read the PEB
Creates a process in suspended mode (likely to inject code)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Dropped file seen in connection with other malware
Drops PE files
Drops PE files to the application program directory (C:\ProgramData)
Drops certificate files (DER)
Found inlined nop instructions (likely shell or obfuscated code)
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
IP address seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
PE / OLE file has an invalid certificate
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: CurrentVersion Autorun Keys Modification
Sigma detected: Direct Autorun Keys Modification
Sigma detected: Potential Persistence Attempt Via Run Keys Using Reg.EXE
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Uses reg.exe to modify the Windows registry
Classification
- System is w10x64
PA.bin.exe (PID: 7604 cmdline:
"C:\Users\ user\Deskt op\PA.bin. exe" MD5: 58DBF2DF74DD9B5F7538C649B494F9C4) cmd.exe (PID: 7304 cmdline:
cmd /c "re g add HKCU \Software\ Microsoft\ Windows\Cu rrentVersi on\RunOnce /v afcdps rv /t REG_ SZ /d C:\P rogramData \afcdpsrv. exe /f" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) conhost.exe (PID: 7308 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) reg.exe (PID: 7404 cmdline:
reg add HK CU\Softwar e\Microsof t\Windows\ CurrentVer sion\RunOn ce /v afcd psrv /t RE G_SZ /d C: \ProgramDa ta\afcdpsr v.exe /f MD5: CDD462E86EC0F20DE2A1D781928B1B0C)
afcdpsrv.exe (PID: 508 cmdline:
"C:\Progra mData\afcd psrv.exe" MD5: 58DBF2DF74DD9B5F7538C649B494F9C4)
afcdpsrv.exe (PID: 2064 cmdline:
"C:\Progra mData\afcd psrv.exe" MD5: 58DBF2DF74DD9B5F7538C649B494F9C4)
- cleanup
⊘No configs have been found
⊘No yara matches
Source: | Author: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): |
Source: | Author: Victor Sergeev, Daniil Yugoslavskiy, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | ReversingLabs: |
Source: | ReversingLabs: | |||
Source: | Virustotal: | Perma Link |
Source: | Static PE information: |
Source: | Binary string: |
Source: | Code function: | 0_2_00403648 | |
Source: | Code function: | 0_2_00408C37 | |
Source: | Code function: | 0_2_00408B4B | |
Source: | Code function: | 12_2_00403648 | |
Source: | Code function: | 12_2_00408C37 | |
Source: | Code function: | 12_2_00408B4B |
Source: | Code function: | 0_2_038F2EB0 | |
Source: | Code function: | 11_3_03992EB0 | |
Source: | Code function: | 12_3_03B32EB0 |
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | IP Address: | ||
Source: | IP Address: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Code function: | 0_2_004075EC |
Source: | File created: | Jump to dropped file |
Source: | Code function: | 0_2_00FF0CD8 | |
Source: | Code function: | 0_2_00FF066E | |
Source: | Code function: | 0_2_00FF11E5 | |
Source: | Code function: | 0_2_00FF0B72 | |
Source: | Code function: | 0_2_00FF10E8 | |
Source: | Code function: | 0_2_00FF1084 | |
Source: | Code function: | 0_2_00FF19C5 | |
Source: | Code function: | 0_2_00FF114C | |
Source: | Code function: | 0_2_02802000 | |
Source: | Code function: | 0_2_02801FC2 | |
Source: | Code function: | 0_2_02801F6F | |
Source: | Code function: | 11_3_00B01084 | |
Source: | Code function: | 11_3_00B010E8 | |
Source: | Code function: | 11_3_00B00CD8 | |
Source: | Code function: | 11_3_00B0114C | |
Source: | Code function: | 11_3_00B0066E | |
Source: | Code function: | 11_3_00B00B72 | |
Source: | Code function: | 11_2_02992000 | |
Source: | Code function: | 11_2_02991FC2 | |
Source: | Code function: | 11_2_02991F6F | |
Source: | Code function: | 12_3_001D1084 | |
Source: | Code function: | 12_3_001D0CD8 | |
Source: | Code function: | 12_3_001D10E8 | |
Source: | Code function: | 12_3_001D114C | |
Source: | Code function: | 12_3_001D066E | |
Source: | Code function: | 12_3_001D0B72 | |
Source: | Code function: | 12_2_02B32000 | |
Source: | Code function: | 12_2_02B31FC2 | |
Source: | Code function: | 12_2_02B31F6F |
Source: | Code function: | 0_2_00405A23 | |
Source: | Code function: | 0_2_00404590 | |
Source: | Code function: | 0_2_00404E54 | |
Source: | Code function: | 0_2_00409A39 | |
Source: | Code function: | 0_2_00404EC2 | |
Source: | Code function: | 0_2_00409AC7 | |
Source: | Code function: | 0_2_00406AC8 | |
Source: | Code function: | 0_2_004050BE | |
Source: | Code function: | 0_2_004098BE | |
Source: | Code function: | 0_2_00405159 | |
Source: | Code function: | 0_2_00409B13 | |
Source: | Code function: | 0_2_0040511E | |
Source: | Code function: | 0_2_00409136 | |
Source: | Code function: | 0_2_00404DD2 | |
Source: | Code function: | 0_2_004075EC | |
Source: | Code function: | 0_2_02800000 | |
Source: | Code function: | 0_2_038FBBF0 | |
Source: | Code function: | 0_2_0391BEA0 | |
Source: | Code function: | 0_2_038F2EB0 | |
Source: | Code function: | 0_2_0391C6E0 | |
Source: | Code function: | 0_2_03901210 | |
Source: | Code function: | 0_2_0395C230 | |
Source: | Code function: | 0_2_0391B920 | |
Source: | Code function: | 0_2_038F8D40 | |
Source: | Code function: | 0_2_0391E570 | |
Source: | Code function: | 0_2_03916D70 | |
Source: | Code function: | 0_2_03900080 | |
Source: | Code function: | 11_3_0399BBF0 | |
Source: | Code function: | 11_3_03992EB0 | |
Source: | Code function: | 11_3_039BBEA0 | |
Source: | Code function: | 11_3_039BC6E0 | |
Source: | Code function: | 11_3_039A1210 | |
Source: | Code function: | 11_3_039FC230 | |
Source: | Code function: | 11_3_039BB920 | |
Source: | Code function: | 11_3_03998D40 | |
Source: | Code function: | 11_3_039BE570 | |
Source: | Code function: | 11_3_039B6D70 | |
Source: | Code function: | 11_3_039A0080 | |
Source: | Code function: | 11_2_02990000 | |
Source: | Code function: | 12_3_03B3BBF0 | |
Source: | Code function: | 12_3_03B32EB0 | |
Source: | Code function: | 12_3_03B5BEA0 | |
Source: | Code function: | 12_3_03B5C6E0 | |
Source: | Code function: | 12_3_03B9C230 | |
Source: | Code function: | 12_3_03B41210 | |
Source: | Code function: | 12_3_03B5B920 | |
Source: | Code function: | 12_3_03B5E570 | |
Source: | Code function: | 12_3_03B56D70 | |
Source: | Code function: | 12_3_03B38D40 | |
Source: | Code function: | 12_3_03B40080 | |
Source: | Code function: | 12_2_00405A23 | |
Source: | Code function: | 12_2_00404590 | |
Source: | Code function: | 12_2_00404E54 | |
Source: | Code function: | 12_2_00409A39 | |
Source: | Code function: | 12_2_00404EC2 | |
Source: | Code function: | 12_2_00409AC7 | |
Source: | Code function: | 12_2_00406AC8 | |
Source: | Code function: | 12_2_004050BE | |
Source: | Code function: | 12_2_004098BE | |
Source: | Code function: | 12_2_00405159 | |
Source: | Code function: | 12_2_00409B13 | |
Source: | Code function: | 12_2_0040511E | |
Source: | Code function: | 12_2_00409136 | |
Source: | Code function: | 12_2_00404DD2 | |
Source: | Code function: | 12_2_004075EC | |
Source: | Code function: | 12_2_02B30000 |
Source: | Dropped File: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Process created: |
Source: | Classification label: |
Source: | Code function: | 0_2_00405A23 |
Source: | Code function: | 0_2_02800C75 |
Source: | Code function: | 0_2_00402AB8 |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | Static PE information: |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: | ||
Source: | Virustotal: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | File read: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Static file information: |
Source: | Static PE information: |
Source: | Binary string: |
Source: | Code function: | 0_2_004063A7 | |
Source: | Code function: | 0_2_00404693 | |
Source: | Code function: | 0_2_004063A7 | |
Source: | Code function: | 0_2_004032CF | |
Source: | Code function: | 0_2_00406AA9 | |
Source: | Code function: | 0_2_0040120E | |
Source: | Code function: | 0_2_00402811 | |
Source: | Code function: | 0_2_00408C9A | |
Source: | Code function: | 0_2_00408D06 | |
Source: | Code function: | 0_2_00402D69 | |
Source: | Code function: | 0_2_004019A4 | |
Source: | Code function: | 0_2_004044ED | |
Source: | Code function: | 0_2_0040450D | |
Source: | Code function: | 0_2_00401E91 | |
Source: | Code function: | 0_2_004036B7 | |
Source: | Code function: | 0_2_00402EC0 | |
Source: | Code function: | 0_2_00402ED1 | |
Source: | Code function: | 0_2_00401EC9 | |
Source: | Code function: | 0_2_004026DD | |
Source: | Code function: | 0_2_004014CC | |
Source: | Code function: | 0_2_004074F3 | |
Source: | Code function: | 0_2_00408AF4 | |
Source: | Code function: | 0_2_00401669 | |
Source: | Code function: | 0_2_00401BB9 | |
Source: | Code function: | 0_2_00401BD0 | |
Source: | Code function: | 0_2_00403005 | |
Source: | Code function: | 0_2_004041A7 | |
Source: | Code function: | 0_2_004019D0 | |
Source: | Code function: | 0_2_0040769A | |
Source: | Code function: | 0_2_004078FE | |
Source: | Code function: | 0_2_0040790D |
Source: | File created: | Jump to dropped file |
Source: | File created: | Jump to dropped file |
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior |
Source: | Registry key monitored for changes: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Source: | API coverage: |
Source: | Thread sleep time: | Jump to behavior |
Source: | Last function: |
Source: | Code function: | 0_2_00403648 | |
Source: | Code function: | 0_2_00408C37 | |
Source: | Code function: | 0_2_00408B4B | |
Source: | Code function: | 12_2_00403648 | |
Source: | Code function: | 12_2_00408C37 | |
Source: | Code function: | 12_2_00408B4B |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Code function: | 0_2_00FF143D |
Source: | Code function: | 0_2_02800000 | |
Source: | Code function: | 0_2_02800B25 | |
Source: | Code function: | 0_2_02800ED5 | |
Source: | Code function: | 0_2_02801B63 | |
Source: | Code function: | 0_2_02801174 | |
Source: | Code function: | 0_2_02801175 | |
Source: | Code function: | 11_2_02990000 | |
Source: | Code function: | 11_2_02990B25 | |
Source: | Code function: | 11_2_02990ED5 | |
Source: | Code function: | 11_2_02991175 | |
Source: | Code function: | 11_2_02991174 | |
Source: | Code function: | 11_2_02991B63 | |
Source: | Code function: | 12_2_02B30000 | |
Source: | Code function: | 12_2_02B30B25 | |
Source: | Code function: | 12_2_02B30ED5 | |
Source: | Code function: | 12_2_02B31175 | |
Source: | Code function: | 12_2_02B31174 | |
Source: | Code function: | 12_2_02B31B63 |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior |
Source: | Code function: | 0_2_00404590 |
Source: | Key value queried: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 2 Command and Scripting Interpreter | 1 Registry Run Keys / Startup Folder | 11 Process Injection | 1 Masquerading | OS Credential Dumping | 1 Query Registry | Remote Services | 1 Archive Collected Data | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 1 DLL Side-Loading | 1 Registry Run Keys / Startup Folder | 1 Modify Registry | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | 1 Clipboard Data | 1 Non-Standard Port | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | 1 DLL Side-Loading | 1 Virtualization/Sandbox Evasion | Security Account Manager | 1 Virtualization/Sandbox Evasion | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Ingress Tool Transfer | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 11 Process Injection | NTDS | 2 Process Discovery | Distributed Component Object Model | Input Capture | 2 Non-Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 Deobfuscate/Decode Files or Information | LSA Secrets | 1 File and Directory Discovery | SSH | Keylogging | 2 Application Layer Protocol | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 3 Obfuscated Files or Information | Cached Domain Credentials | 14 System Information Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 1 DLL Side-Loading | DCSync | Remote System Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.