Managed XDR

izmadza.exe (Upatre) — malware analysis report

File info

Filename
izmadza.exe
File type
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
File size
51.3 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
5e88c063a3bbf41fd026a4a98723a43547d884d2
SHA256
a4ba261b5ed33c688af7d9e863a6bbce6c53f7c32d915102fa10388433c6b870
MD5
a2c059ae6c4dd496acd662cc713aa0c9

Malwares

  • Upatre

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_polymorphic: Creates a modified copy of itself
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1497.001 antivm_queries_computername: Retrieves the computer name
T1070 stealth_window: A process created a hidden window
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1497.001 antivm_queries_computername: Retrieves the computer name

Other

yara_rules: Static rules
static_pe_anomaly: The PE file structure contains anomalies
creates_exe: Creates executable files in the file system
executes_dropped_exe: Executes dropped exe files
no_graphical_activity: No graphic activity
get_policy_info: Retrieves information about a Policy object
pe_overlay: PE file contains overlay

Related reports