Managed XDR

7917ac7016b9de19b92560185a132278.virus — malware analysis report

File info

Filename
7917ac7016b9de19b92560185a132278.virus
File type
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
File size
14 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
35a7816e68ca3287b89b92408872ce7100ab509b
SHA256
b8798fdd7c589985c8ff2d677000bd9475d6205267cc6a93537727b8223c8b27
MD5
7917ac7016b9de19b92560185a132278

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1480 system_default_lang_id_present: Checks the system language
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity