Managed XDR

85b1e13ecc85747ced6d61f3151cb8e9.virus — malware analysis report

File info

Filename
85b1e13ecc85747ced6d61f3151cb8e9.virus
File type
PE32 executable (GUI) Intel 80386, for MS Windows
File size
254.1 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
6ae6160614d0bcc5c845c5126145bb7f36893e15
SHA256
2c473ccf7aab68329bd347772a7a3b85036127b353884994bfe0e8c0e378eeb0
MD5
85b1e13ecc85747ced6d61f3151cb8e9

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
non_quadratic_icon: Icon is not square
creates_in_windows: Creates files in the Windows directory
no_graphical_activity: No graphic activity
require_administrator: Requests administrator privileges
pe_overlay: PE file contains overlay
valid_authenticode: The digital signature has been verified