Managed XDR

home-share-sample-gray...3ca678f7acf5275d018e67 — malware analysis report

File info

Filename
home-share-sample-gray-cde_pe_samples-sample_decompress-20201106-2020_11_6_2_40_54_586440_6f2538cdf2661b560e89cc8711603025-hit-410186cfb33ca678f7acf5275d018e67
File type
PE32 executable (GUI) Intel 80386, for MS Windows
File size
448 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
02328b133cf1edef61d1c051073fa29fc2c83a7b
SHA256
069f4da11e50ca2b616a485c383c742b0d3cba944ec3d9b4c06018b47564ed05
MD5
410186cfb33ca678f7acf5275d018e67

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
process_crashed: One of the processes has failed
no_graphical_activity: No graphic activity
pe_overlay: PE file contains overlay