Total Score | |
Artifacts Database Version | 1.09 |
Artifacts Severity Rule Type | PE32 (gui) |
File System | ||
Modify operating system file | ||
Modify "c:\windows\$ntuninstallq923283$\fdisk.sys" | ||
Modify "c:\windows\$ntuninstallq923283$\usbehub.sys" | ||
Modify "c:\windows\$ntuninstallq923283$\pxinsi64.exe" | ||
Kernel | ||
Execute code with kernel privileges | ||
See kernel behavior tab for detailed information | ||
OS | ||
Enable critical process privileges | ||
Enable "SeLoadDriverPrivilege" | ||
Enable process privileges | ||
Process | ||
Create system object | ||
Creates mutex with name "{E9B1E207-B513-4cfc-86BE-6D6004E5CB9C}" | ||
Create process with hidden window | ||
The process "C:\Windows\$NtUninstallQ923283$\pxinsi64.exe" starts with hidden window | ||
Static | ||
Drop PE file | ||
Drop file "c:\windows\$ntuninstallq923283$\usbehub.sys" | ||
Drop file "c:\windows\$ntuninstallq923283$\fdisk.sys" | ||
Drop file "c:\windows\$ntuninstallq923283$\pxinsi64.exe" | ||
Execute dropped PE file | ||
Execute dropped file "c:\windows\$ntuninstallq923283$\pxinsi64.exe" | ||
- | Anti Analysis | |
- | Device | |
- | Hide Tracks | |
- | Information Stealing | |
- | Injection | |
- | Masquerade | |
- | Misc | |
- | Network | |
- | Persistence | |
- | VBA Macro |