Managed XDR

d95eeae6eefe79266a9d4c24b50228d1.virus — malware analysis report

File info

Filename
d95eeae6eefe79266a9d4c24b50228d1.virus
File type
PE32 executable (GUI) Intel 80386, for MS Windows
File size
339 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
173138893dffde6ab76420d2ddf374bd156024ad
SHA256
e74697ff09577b3ab6ec70d74c6996263199c47a0b00e56448185a0e0f79610e
MD5
d95eeae6eefe79266a9d4c24b50228d1

Signatures

Execution

T1059.001 suspicious_powershell: Creates suspicious powershell process
T1059.001 suspicious_process: Spawns a suspicious process

Privilege Escalation

T1055 injection_failed: The attempt to inject into a process has failed
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1055 injection_failed: The attempt to inject into a process has failed
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
creates_many_processes: Spawns a lot of processes (over 70)
static_pe_anomaly: The PE file structure contains anomalies
no_graphical_activity: No graphic activity
break_limit_exceeded: Warning: function calls limit has been exceeded