Managed XDR

1-b-a-ba520f93d2def35d...c44afaf2b5ba15f45.file — malware analysis report

File info

Filename
1-b-a-ba520f93d2def35da00afc3c915b01db896ed849401ddd2c44afaf2b5ba15f45.file
File type
PE32+ executable (console) x86-64, for MS Windows
File size
10.6 MB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
a195a6356f10a8de82cd546be365e38e29aa12d3
SHA256
ba520f93d2def35da00afc3c915b01db896ed849401ddd2c44afaf2b5ba15f45
MD5
c04a393ad41f49aa268e7e5f1e664eba

Signatures

Execution

T1059.003 executes_dropped_cmd: Executes dropped batch files
T1059.006 drops_python_dll: Drops python dll

Persistence

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1574 dropper_dll: Creates DLL, which is then loaded into the process

Privilege Escalation

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1056.001 infostealer_keylogger: Keylogger (intercepts keystrokes)

Collection

T1056.001 infostealer_keylogger: Keylogger (intercepts keystrokes)

Other

creates_suspended_process: Creates suspended process
creates_exe: Creates executable files in the file system
test_check_service: Starts services
writes_data: Writes big amount of data to disk
pe_overlay: PE file contains overlay