← All malware

77fb832052abc29f8392e50a83571fda0a9a44fc14c485bc9ae58b37ca51b00e

Live Scan Result: Tria.ge
Score
10/10

Threat Level

Known Bad

RansomwareTrojanRatStealerInfostealerSpywareWormBackdoorBankerMinerInstallerBootkitBotnet:6ff1fd60fb5387f3c93619f2e30e125fBotnet:avtostopomBotnet:jajajaBotnet:office04Botnet:rdpDefense EvasionDiscoveryExecutionImpactPersistencePyinstallerThemidaUpx

MITRE Behavior Map

Execution (TA0002)

  • Windows Management Instrumentation (T1047)
  • Scheduled Task (T1053.005)
  • PowerShell (T1059.001)

Persistence (TA0003)

  • Scheduled Task (T1053.005)
  • Bootkit (T1542.003)
  • Windows Service (T1543.003)
  • Registry Run Keys / Startup Folder (T1547.001)

Privilege Escalation (TA0004)

  • Scheduled Task (T1053.005)
  • Windows Service (T1543.003)
  • Registry Run Keys / Startup Folder (T1547.001)

Defense Evasion (TA0005)

  • Direct Volume Access (T1006)
  • File Deletion (T1070.004)
  • Modify Registry (T1112)
  • Virtualization/Sandbox Evasion (T1497)
  • Bootkit (T1542.003)
  • Disable or Modify System Firewall (T1562.004)

Discovery (TA0007)

  • Query Registry (T1012)
  • Internet Connection Discovery (T1016.001)
  • Remote System Discovery (T1018)
  • System Information Discovery (T1082)
  • Network Share Discovery (T1135)
  • Virtualization/Sandbox Evasion (T1497)
  • System Language Discovery (T1614.001)

Command and Control (TA0011)

  • Web Service (T1102)

Impact (TA0040)

  • Inhibit System Recovery (T1490)

Hostnames

9
  1. 1.discord.com
  2. 2.lousta.net
  3. 3.mail-eco.gl.at.ply.gg
  4. 4.mkkuei4kdsz.com
  5. 5.ow5dirasuek.com
  6. 6.steamcommunity.com
  7. 7.t.me
  8. 8.understand-vip.gl.at.ply.gg
  9. 9.xred.mooo.com