Managed XDR

fdsfsdfsfs.one — malware analysis report

File info

Filename
fdsfsdfsfs.one
File type
data
File size
263.5 KB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
2c2e8ac5be2f5109de2ccaa1da336aa57ec00262
SHA256
ae14ffa467df844f61e5cdf977600ddbb628a136950d7bfa64f1e884d56c30fa
MD5
ea1d5988329f9e9ff0f9fbe92650d69d

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
office_embedded: Office document contains embedded executable file(s)
copies_self: Creates a copy of itself
unexpected_exception: Unexpected exception
has_pdb: This executable file has a PDB path
creates_suspended_process: Creates suspended process
access_recyclebin: Manipulation with recyclebin detected
test_check_service: Starts services