Managed XDR

airwin.exe (Hive) — malware analysis report

File info

Filename
airwin.exe
File type
PE32+ executable (console) x86-64, for MS Windows
File size
14.5 MB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
6b50b2402f4edaf99e19e06ab2e8371532258365
SHA256
e7f498e3898cd41e3adcb3933ea15f2727aed189675dad329b06034f2d2dc460
MD5
4a274be2d3631b69068e6bcc976c3865

Malwares

  • Hive

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1056.001 infostealer_keylogger: Keylogger (intercepts keystrokes)

Collection

T1056.001 infostealer_keylogger: Keylogger (intercepts keystrokes)

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
has_pdb: This executable file has a PDB path

Related reports