Managed XDR

f2c4e11fb453dcdd2d1c28cda4b20c23.virus — malware analysis report

File info

Filename
f2c4e11fb453dcdd2d1c28cda4b20c23.virus
File type
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed
File size
132.6 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
ac8d4d27c136fafe8dca98b427b89ab9fe2898d6
SHA256
23ffa5b9c49b0041e580cb65efb99f4b341357c39fe89beac4bc5ac87efbadf7
MD5
f2c4e11fb453dcdd2d1c28cda4b20c23

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_polymorphic: Creates a modified copy of itself
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1027.002 packer_upx: The executable file is compressed using UPX
T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Collection

T1074.001 access_recyclebin: Manipulation with recyclebin detected

Impact

T1486 modifies_files: Cryptolocker indicators detected (renamed 500 or more files)
T1485 deletes_files: Removes 100 or more files from C: drive

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
writes_data: Writes big amount of data to disk
pe_overlay: PE file contains overlay