Managed XDR

remote-access-windows32-offline.exe_ico — malware analysis report

File info

Filename
remote-access-windows32-offline.exe_ico
File type
PE32 executable (GUI) Intel 80386, for MS Windows
File size
38.6 MB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
f01ed4579c20ff16b4a6f3242f25b039218bd1fe
SHA256
b1eef6074881bda43ee0aeec97cd44d8c49441de9f2386b6b5a953c8e7d22d33
MD5
c3435482580ab910eafa50f129a5bda2

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497.002 antivm_usbstor: Reads information about usbdevices from regkey
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1555.004 windows_credential_manager: Acquire credentials from the Windows Credential Manager

Discovery

T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497.002 antivm_usbstor: Reads information about usbdevices from regkey

Other

yara_rules: Static rules
process_crashed: One of the processes has failed
suspicious_network_port: Performs TCP or UDP request to non-standard port
test_check_service: Starts services
writes_data: Writes big amount of data to disk
pe_overlay: PE file contains overlay
static_big_overlay: Executable file contains an enormously big overlay
ce_info: SimpleHelp Configuration Data found
valid_authenticode: The digital signature has been verified