Managed XDR

5c62ac89e3ec67da6e062a821a9e89f3.virus — malware analysis report

File info

Filename
5c62ac89e3ec67da6e062a821a9e89f3.virus
File type
PE32 executable (GUI) Intel 80386, for MS Windows
File size
474.1 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
2dbe3c7c6bce8535a88b1d9513e75c49bf83837c
SHA256
11139080831ec18c423048f3ece07433d66c65c236bd93696e5e2598dc79a989
MD5
5c62ac89e3ec67da6e062a821a9e89f3

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
process_crashed: One of the processes has failed
no_graphical_activity: No graphic activity
pe_overlay: PE file contains overlay