Managed XDR

f8e1288b9960ba3161ad6e907d25ee55.virus — malware analysis report

File info

Filename
f8e1288b9960ba3161ad6e907d25ee55.virus
File type
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
File size
14 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
42c62e7b5c0ccbac0375f5e58d5408639290ff23
SHA256
28f0442e9b21e9120800541f53777d18bcc0d8f9a57edda96544d6d43f4f850d
MD5
f8e1288b9960ba3161ad6e907d25ee55

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1480 system_default_lang_id_present: Checks the system language
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity