Managed XDR

file-of-information — malware analysis report

File info

Filename
file-of-information
File type
PE32 executable (GUI) Intel 80386, for MS Windows
File size
942 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
4376c70d9fbbdb2889f96941c63acab1243eec10
SHA256
3da7235020f18383a9890c35ce6486c414701291722625660792c115c9120133
MD5
809c208f9af9ad46050ea820a008261c

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1033 sam_users_discovery: Enumerates users or groups in system with SAM API
T1518 locates_browser: Attempts to identify where browsers are installed
T1087.001 local_account_discovery: Enumerates local accounts

Other

yara_rules: Static rules
creates_exe: Creates executable files in the file system
executes_dropped_exe: Executes dropped exe files
no_graphical_activity: No graphic activity
create_rpc_bindings: Creates RPC connection
require_administrator: Requests administrator privileges
origin_langid: Unconventional language of the executable file
creates_in_programdata: Creates files in the ProgramData directory
checktokenmembership: Checks user token with CheckTokenMembership call