Managed XDR

odin.rar — malware analysis report

File info

Filename
odin.rar
File type
RAR archive data, v5
File size
342.8 KB
First seen
Last seen

Environment

win7/x64 en

Hashes

SHA1
17bb91d4c75c1ee3903426a17bf44d3b2329de77
SHA256
bbd3963bfb1ed705116b21f18d0b031710d01ce37f9bda5c415dab78e5fafdc0
MD5
7afe2047ff0fa0ae8d60f274eca9805b

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1070 stealth_window: A process created a hidden window
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
creates_exe: Creates executable files in the file system
executes_dropped_exe: Executes dropped exe files
require_administrator: Requests administrator privileges
message_box: Displays a message
get_policy_info: Retrieves information about a Policy object