Managed XDR

c-users-user-appdata-l...f-01477f59b820-dwm.exe — malware analysis report

File info

Filename
c-users-user-appdata-local-b1316732-ef31-5c13-e85f-01477f59b820-dwm.exe
File type
PE32 executable (GUI) Intel 80386, for MS Windows
File size
2 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
cc95f4e3f6041061aa88c17b0dbe9cf323fb6172
SHA256
08e5baaeb63b2ada2039da986336af93a076a24b6a75a4d0fb54ac0ae190a5dc
MD5
468ce488aeeb602caeec339db1b7807c

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1070 yara_rules: Static rules
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_process_token: Opens the access token associated with a process

Other

no_graphical_activity: No graphic activity