Managed XDR

output.bin (Ozone RAT) — malware analysis report

File info

Filename
output.bin
File type
PE32 executable (GUI) Intel 80386, for MS Windows
File size
56 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
9825792e710d449351311dd45f378c3b79fb58d0
SHA256
14c2d6607e7a31b7bed5cb35d4ce31bfd022ba70534964ac591fa25da318ec10
MD5
4eefa0d2cb074e87630893f748b6f8c5

Malwares

  • Ozone RAT

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
dns_without_resolve: DNS query without a response
no_graphical_activity: No graphic activity

Related reports