Managed XDR

a45b5a161cb0fcdc40bc13b13e211efa.virus — malware analysis report

File info

Filename
a45b5a161cb0fcdc40bc13b13e211efa.virus
File type
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
File size
14 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
3fabde9285426aae29d308c06749448afb67864d
SHA256
b1969c9b96566796cc78f2e5a784df2df64150a7bf3744af5a13438ed0b9aa04
MD5
a45b5a161cb0fcdc40bc13b13e211efa

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1480 system_default_lang_id_present: Checks the system language
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity