Tags:
family:acrstealer family:sectoprat defense_evasion discovery execution persistence privilege_escalation rat spyware stealer trojan
Checks processor information in registry
Enumerates system info in registry
Modifies data under HKEY_USERS
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Browser Information Discovery
Command and Scripting Interpreter: PowerShell
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Accesses cryptocurrency files/wallets, possible credential harvesting
Adds Run key to start application
Checks installed software on the system
Reads user/profile data of local email clients
Reads user/profile data of web browsers
Badlisted process makes network request
Detects SectopRAT aka Arechclient2
Family: ACR stealer,GrMsk
Suspicious use of NtCreateUserProcessOtherParentProcess
C2 Extraction:
media.hazelnook.cc
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.