Managed XDR

scardsvr.exe — malware analysis report

File info

Filename
scardsvr.exe
File type
PE32 executable (console) Intel 80386, for MS Windows
File size
1.8 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
4146ab2fa1463bd8df044b070c542a8a900e6db6
SHA256
76d23f7b5e31101d394501e8d7a15662808812373da486add607f4f6327e6815
MD5
0af7f32fda8eb7f20a118ad82992a2eb

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
has_pdb: This executable file has a PDB path
pe_overlay: PE file contains overlay