Managed XDR

fiut.exe — malware analysis report

File info

Filename
fiut.exe
File type
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
File size
940.6 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
7318ccd7e74d898f071845db9e72e8feb60696d1
SHA256
52124259f25e14cd8acde68b50eee898240e75954d7307f13e1ecace1738e7f6
MD5
26da2e6663f37d38427ef0610e54c39f

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1480 system_default_lang_id_present: Checks the system language
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
creates_in_programdata: Creates files in the ProgramData directory
pe_overlay: PE file contains overlay