Managed XDR

media-daniel-ssd2-data...3a1474d80db12ff3fe8d8d — malware analysis report

File info

Filename
media-daniel-ssd2-datasets-bodmas-virustotal-executables-amber-malicious-5fd4c3fc1ce65f2f0b7cf905e1e116e6d70bacd0783a1474d80db12ff3fe8d8d
File type
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
File size
419 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
ec02df356e4f29c27982cdce392cbf6c66217927
SHA256
b9e7d3bfa40799101d195fec620a9f94f986f39285e8509b04025946c4d99da9
MD5
663de2579d3a383677931ef60caa80e4

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
process_crashed: One of the processes has failed
unexpected_exception: Unexpected exception
no_graphical_activity: No graphic activity