Managed XDR

c-naye-kyf7-m5n7pyor-m...-flx4oxj-gxhf9.tar.bz2 — malware analysis report

File info

Filename
c-naye-kyf7-m5n7pyor-mixyb-flx4oxj-gxhf9.tar.bz2
File type
PE32 executable (GUI) Intel 80386, for MS Windows
File size
4 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
9dbb9b5d2a53545a09708b2785d3fb68ebf1dbd6
SHA256
2c5dad34d3bd06c194dfc97f12844f7bcf1929c9ceae0be1593bc2ad0babfefc
MD5
23ea4fe434fd9af80022ac80114a60ac

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 unnamed_memory_regions_contains_pe: One or several unnamed memory regions are PE files
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Command and Control

T1071.001 network_http: Performs HTTP requests

Other

yara_rules: Static rules
suricata_alert: Malicious traffic detected
no_graphical_activity: No graphic activity
message_box: Displays a message