Managed XDR

config.exe — malware analysis report

File info

Filename
config.exe
File type
RFC 822 mail, ASCII text, with very long lines, with CRLF, LF line terminators
File size
1.7 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
4141d4d01e21d314065f6fd2265942338603feb9
SHA256
55ca818ff7505ce99f9df82278e270935be7d350e5eb07d8d365bc357b5dad0e
MD5
5ae6bef5e674b4a068d6e90ca7f27149

Signatures

Execution

T1203 office_write_exe: Office document dropped an executable file
T1106 susp_callbacks: Suspicious usage of some WinAPI with callbacks

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

office_embedded: Office document contains embedded executable file(s)
static_pe_anomaly: The PE file structure contains anomalies
creates_exe: Creates executable files in the file system
no_graphical_activity: No graphic activity
break_limit_exceeded: Warning: function calls limit has been exceeded
message_box: Displays a message
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card