Total Score | |
Artifacts Database Version | 1.09 |
Artifacts Severity Rule Type | PE32 (gui) |
Kernel | Execute code with kernel privileges | ||
See kernel behavior tab for detailed information | |||
OS | Enable critical process privileges | ||
Enable "SeLoadDriverPrivilege" | |||
File System | Modify operating system file | ||
Modify "c:\windows\$ntuninstallq923283$\fdisk.sys" | |||
Modify "c:\windows\$ntuninstallq923283$\usbehub.sys" | |||
Modify "c:\windows\$ntuninstallq923283$\pxinsi64.exe" | |||
Process | Create system object | ||
Creates mutex with name "{E9B1E207-B513-4cfc-86BE-6D6004E5CB9C}" | |||
OS | Enable process privileges | ||
Process | Create process with hidden window | ||
The process "C:\Windows\$NtUninstallQ923283$\pxinsi64.exe" starts with hidden window | |||
Static | Drop PE file | ||
Drop file "c:\windows\$ntuninstallq923283$\usbehub.sys" | |||
Drop file "c:\windows\$ntuninstallq923283$\fdisk.sys" | |||
Drop file "c:\windows\$ntuninstallq923283$\pxinsi64.exe" | |||
Static | Execute dropped PE file | ||
Execute dropped file "c:\windows\$ntuninstallq923283$\pxinsi64.exe" |