Managed XDR

e415e65ca4377bdfeb7fe875a8b86a72.virus — malware analysis report

File info

Filename
e415e65ca4377bdfeb7fe875a8b86a72.virus
File type
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed
File size
132.6 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
b19032c649237240d88197c210edf0f993412ae2
SHA256
84d0def6f6be8eedc4a8622b665fe1e9377f35a4e77b47175b1f280e059888d1
MD5
e415e65ca4377bdfeb7fe875a8b86a72

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_polymorphic: Creates a modified copy of itself
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1027.002 packer_upx: The executable file is compressed using UPX
T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Collection

T1074.001 access_recyclebin: Manipulation with recyclebin detected

Impact

T1486 modifies_files: Cryptolocker indicators detected (renamed 500 or more files)
T1485 deletes_files: Removes 100 or more files from C: drive

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
writes_data: Writes big amount of data to disk
pe_overlay: PE file contains overlay