Managed XDR

287976119 — malware analysis report

File info

Filename
287976119
File type
ISO-8859 text, with very long lines, with CRLF, CR, LF line terminators
File size
73.2 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
38a8b3676045054c67f557809dafe6871d5f3f4d
SHA256
affbefc0bde756ebb08f66a4ad293b4ae653466a6a624118e7289ef5b945e6c0
MD5
57659e2c17eadb60aee264457c8f8e2c

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1083 checks_recent_files: Attempt to check recently opened files through registry

Other

yara_rules: Static rules
get_policy_info: Retrieves information about a Policy object
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card