Managed XDR

ft.flingitrainerr.38.113.66607.zip — malware analysis report

File info

Filename
ft.flingitrainerr.38.113.66607.zip
File type
Zip archive data, at least v2.0 to extract
File size
6.3 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
8e6379bff97d27441cd3bc9a7097c44adb742a59
SHA256
0fd79152f49d2a804d5f2f5fe53085e595ac5c70d86b15b978ddf2c3dd417d48
MD5
f90eb0846505f325df82bab10af03c73

Signatures

Persistence

T1574 dropper_dll: Creates DLL, which is then loaded into the process

Privilege Escalation

T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
process_crashed: One of the processes has failed
no_graphical_activity: No graphic activity
valid_authenticode: The digital signature has been verified
has_pdb: This executable file has a PDB path
test_check_service: Starts services
pe_overlay: PE file contains overlay