Detections
NOT FOUND
Mitre Signatures
8 INFO
IDS Rules
NOT FOUND
Sigma Rules
2 LOW
Dropped Files
NOT FOUND
Network comms
1 IP
Behavior Tags
idle
MITRE ATT&CK Tactics and Techniques
Persistence
TA0003
Privilege Escalation
TA0004
Defense Evasion
TA0005
Credential Access
TA0006
Discovery
TA0007
Collection
TA0009
Crowdsourced Sigma Rules
CRITICAL 0
HIGH 0
MEDIUM 0
LOW 2
Matches rule Failed Code Integrity Checks by Thomas Patzke
Matches rule Process Start From Suspicious Folder by frack113
-
Sigma rule cannot be loaded.
Network Communication
IP Traffic
23.216.147.64:443 (TCP)
Behavior Similarity Hashes
C2AE
fe66e54118bb12b06dcbabb6c2d17206
Microsoft Sysinternals
7936d7d880ff24e528d0bd071579d079
Zenbox
e38942f1a539ab5db2d585a98f9bf167
File system actions
Files Opened
C:\Users\user\Desktop\pes2013.exe
C:\Windows\AppPatch\sysmain.sdb
C:\Windows\Globalization\Sorting\sortdefault.nls
C:\Windows\SysWOW64\ADVAPI32.dll
C:\Windows\SysWOW64\CRYPTBASE.dll
C:\Windows\SysWOW64\CoreMessaging.dll
C:\Windows\SysWOW64\CoreUIComponents.dll
C:\Windows\SysWOW64\DCIMAN32.dll
C:\Windows\SysWOW64\DDRAW.dll
C:\Windows\SysWOW64\DINPUT8.dll
Registry actions
Registry Keys Opened
HKEY_CURRENT_USER\Software\Classes
HKEY_CURRENT_USER\Software\Classes\Local Settings
HKEY_CURRENT_USER\Software\Microsoft\CTF\DirectSwitchHotkeys
HKEY_CURRENT_USER\Software\Microsoft\Direct3D
HKEY_CURRENT_USER\Software\Microsoft\Direct3D\Drivers
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
HKEY_CURRENT_USER\System\CurrentControlSet\Control\GraphicsDrivers\Scheduler
HKEY_CURRENT_USER_Classes
HKEY_CURRENT_USER_Classes\AppID\GameBarPresenceWriter.exe
HKEY_CURRENT_USER_Classes\CLSID\{0134A8B2-3407-4B45-AD25-E9F7C92A80BC}
Registry Keys Set
HKEY_CURRENT_USER\SOFTWARE\Microsoft\XboxLive
Process and service actions
Processes Created
%SAMPLEPATH%\pes2013.exe
Shell Commands
"%SAMPLEPATH%\pes2013.exe"
%SAMPLEPATH%
Processes Terminated
%SAMPLEPATH%
%windir%\System32\svchost.exe -k WerSvcGroup
wmiadap.exe /F /T /R
Processes Tree
2200 - %windir%\System32\svchost.exe -k WerSvcGroup
2644 - %SAMPLEPATH%
2904 - wmiadap.exe /F /T /R
2940 - %WINDIR%\explorer.exe
2952 - %windir%\system32\wbem\wmiprvse.exe
6244 - "C:\Windows\System32\GameBarPresenceWriter.exe" -ServerName:Windows.Gaming.GameBar.Internal.PresenceWriterServer
6564 - "C:\Users\user\Desktop\pes2013.exe"
812 - %SAMPLEPATH%\pes2013.exe