Managed XDR

6c4f4693181c8e8a2099c50bf8f8c56e.virus — malware analysis report

File info

Filename
6c4f4693181c8e8a2099c50bf8f8c56e.virus
File type
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
File size
14 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
30112a45c2d2258ba604b53c21fb66e08a3b8897
SHA256
8dd3b973138d03bffe7fbb348c360ea33451ec1e7feac811e6630a1473f6a0f4
MD5
6c4f4693181c8e8a2099c50bf8f8c56e

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity