Managed XDR

lime-crypter.exe — malware analysis report

File info

Filename
lime-crypter.exe
File type
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size
141.5 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
b962772f9eea41051423f6efef70b535a8381761
SHA256
524ae896f2e60e84e7047c11ca5b0ba5b137cb29c4731ea1c1337bc7199ae518
MD5
af8a40398f79697e05a2db13b32cd6b2

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
has_pdb: This executable file has a PDB path
get_policy_info: Retrieves information about a Policy object