Managed XDR

chertezhi-fleshka.zip — malware analysis report

File info

Filename
chertezhi-fleshka.zip
File type
Zip archive data, at least v1.0 to extract
File size
1.4 MB
First seen
Last seen

Environment

win7/x64 en

Hashes

SHA1
98821a09c8f3746bea01c55d3c85cd7caf796e9b
SHA256
ecf066e59160fc789d5d66469065442fd0947af2135f36dae9c3d1935169068e
MD5
4ebcdf224ecee00581444bd17a4dc408

Signatures

Execution

T1204.002 mimics_extension: Attempts to mimic the file extension

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1036 mimics_extension: Attempts to mimic the file extension
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
only_exec_in_archive: The archive contains only an executable file
no_graphical_activity: No graphic activity
has_pdb: This executable file has a PDB path
pe_overlay: PE file contains overlay