Managed XDR

tmpfilename (TrickBot) — malware analysis report

File info

Filename
tmpfilename
File type
PE32 executable (GUI) Intel 80386, for MS Windows
File size
517.5 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
0d067a2e596ef17c448751b64ee9c3cec5ed3602
SHA256
3b94b5348f01ec9c7f6a64b3160a18d2ec41b1fa7b562939755e8d05b2e7ce96
MD5
aa54c60c18aee4e4185b1006691273f8

Malwares

  • TrickBot

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
static_pe_duplicate_sections: The PE file structure contains anomalies: duplicate section names
no_graphical_activity: No graphic activity

Related reports