Managed XDR

camtasia.studio.v5.0.2.rar — malware analysis report

File info

Filename
camtasia.studio.v5.0.2.rar
File type
Zip archive data, at least v1.0 to extract
File size
31.3 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
da0bcacdc1e3cbef6bdd8549f516187027f0c009
SHA256
8ca8b6d53469c9bc4845fc4810f979b9e3bb5bf874835c9b59dc29f4b78b8ffd
MD5
f915b4a8e424f25ee03900a498a64f8b

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497 antidbg_windows: Checks for open windows typical for debuggers and forensic tools
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497 antidbg_windows: Checks for open windows typical for debuggers and forensic tools
T1518.001 antidbg_devices: Checks for devices typical for debuggers and forensic tools

Other

yara_rules: Static rules
process_crashed: One of the processes has failed
static_pe_duplicate_sections: The PE file structure contains anomalies: duplicate section names
no_graphical_activity: No graphic activity