Managed XDR

cmd.exe — malware analysis report

File info

Filename
cmd.exe
File type
PE32+ executable (console) x86-64, for MS Windows
File size
4 MB
First seen
Last seen

Environment

win7/x64 en

Hashes

SHA1
3f5c1e7119906230f55c4da0efad00cdc17d02ed
SHA256
5fe985ddb4de72c71ef98d3d2ae251bd7dd2e517991098a4fd3214753adbd0e4
MD5
46c65b477d694d9bd59a8dc20a60597a

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules