Managed XDR

mspub.exe — malware analysis report

File info

Filename
mspub.exe
File type
PE32 executable (GUI) Intel 80386, for MS Windows
File size
9.7 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
b61a2b3d38b2479018998b080ea003b188e8fcd0
SHA256
1eb271376a4f27b4ca7d8a37388b9e75b9eae5dc1d5c65b5f00a2a249800cfb7
MD5
095f67f6ca6cdd96429d740a0d16fb67

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
has_pdb: This executable file has a PDB path