Managed XDR

3ed830b0803b63aca0a826...5019d55f25a1f4_new.exe (ALPHV) — malware analysis report

File info

Filename
3ed830b0803b63aca0a82661475c863801afd2e2b03c2675b05019d55f25a1f4_new.exe
File type
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
File size
2.9 MB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
83d6ffc9cebd2b4f7da64e6896a98bc3c1fc4225
SHA256
308a282009ff712d749fa7da347c62a206fcf9765bf987a26cad3b34caaf6cc1
MD5
6e13f1f63d069a9f997a845cf7db8b64

Malwares

  • ALPHV

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497.002 antivm_usbstor: Reads information about usbdevices from regkey
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1555.004 windows_credential_manager: Acquire credentials from the Windows Credential Manager

Discovery

T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497.002 antivm_usbstor: Reads information about usbdevices from regkey

Other

yara_rules: Static rules
ce_info: Blackcat Configuration Data found
suspicious_network_port: Performs TCP or UDP request to non-standard port
test_check_service: Starts services
writes_data: Writes big amount of data to disk

Related reports

Managed XDR