Managed XDR

unknown (Symmi) — malware analysis report

File info

Filename
unknown
File type
PE32 executable (GUI) Intel 80386, for MS Windows
File size
272 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
b0f6594123bf99eb7b4a7ec91c462d3ae4974c6f
SHA256
48432588a49c69cf82dca732c5263ff9effee769de618303daef1e2364a6368c
MD5
6a37fd4a4fb96b25365d2ae3ee7fa19c

Malwares

  • Symmi

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules

Related reports