Managed XDR

blackcat-unknown.exe (ALPHV) — malware analysis report

File info

Filename
blackcat-unknown.exe
File type
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
File size
2.2 MB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
7abfff5b7ae668c100d2b94ba46ed5df6a881503
SHA256
5db0209455e36b2dc2f30f79c758e6cd178b5609ff24be841d6266f1e150a2b7
MD5
60761457acb89bbb97bcdbc1d431d6a8

Malwares

  • ALPHV

Signatures

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data

Other

yara_rules: Static rules
ce_info: Blackcat Configuration Data found
suspicious_network_port: Performs TCP or UDP request to non-standard port
pe_overlay: PE file contains overlay

Related reports

Managed XDR