Managed XDR

b7e2df9bdbff5c577d7afe...00400000_reconstructed — malware analysis report

File info

Filename
b7e2df9bdbff5c577d7afe9e3ceb7a1ff337e6b19eab9a319c4e033dae16f37c_dump7_0x00400000_reconstructed
File type
PE32 executable (GUI) Intel 80386, for MS Windows
File size
140 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
bb8fe51e51766cbc8cbfdd66e3618e0d1e6e81d9
SHA256
a21e78ca835a605321c2922a32999c359440821ca10e3c524e3147a9c9eb3240
MD5
078e70accbe4ad7ebf786fcc64a1b20a

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.001 static_overlay_padding: Overlay contents padding
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
pe_overlay: PE file contains overlay