Managed XDR

remote-accesslauncher_icon.exe — malware analysis report

File info

Filename
remote-accesslauncher_icon.exe
File type
PE32 executable (GUI) Intel 80386, for MS Windows
File size
388.4 KB
First seen
Last seen

Environment

w10/x86 en

Hashes

SHA1
2337a6674f15689cf4f0982ca35a2b6ec7619165
SHA256
cdba6f935aa0712669f0bc2701b68009c386e0ecf477caa48d690a56e532db92
MD5
c2f88329ea53637fe55d4af8a4778f11

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
require_administrator: Requests administrator privileges
writes_data: Writes big amount of data to disk