Managed XDR

eab1525ea5b35e5fda555f386f6a89fd.virus — malware analysis report

File info

Filename
eab1525ea5b35e5fda555f386f6a89fd.virus
File type
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has command line arguments, Archive, ctime=Mon Feb 27 19:25:19 2017, mtime=Mon Feb 27 19:25:19 2017, atime=Thu Nov 27 17:44:14 2014, length=750320, window=hide
File size
708 Bytes
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
9b8aa5cfa60383b210c5ed54b333057d43ea8bb3
SHA256
8f094692797992c4f293046b04e9183a4d1cccd03b88d62edcb92bcc33e3892b
MD5
eab1525ea5b35e5fda555f386f6a89fd

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
create_process_failed: Could not start the process
unexpected_exception: Unexpected exception
no_graphical_activity: No graphic activity
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object