Managed XDR

virusshare_03373199b2477c3e34aa0e47eca1a1de — malware analysis report

File info

Filename
virusshare_03373199b2477c3e34aa0e47eca1a1de
File type
PE32 executable (GUI) Intel 80386, for MS Windows
File size
1.9 MB
First seen
Last seen

Environment

w10/x86 en

Hashes

SHA1
0b06afeadca4cfcc262b4c93f15eb881151993e2
SHA256
4039ae3dea16b0a5ec99b7333210d3b7f6e8773115444f4f30525bd09b47bfb3
MD5
03373199b2477c3e34aa0e47eca1a1de

Signatures

Execution

T1106 susp_callbacks: Suspicious usage of some WinAPI with callbacks

Privilege Escalation

T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1135 server_share_info: Retrieves information about each shared resource on a server

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
create_rpc_bindings: Creates RPC connection
access_recyclebin: Manipulation with recyclebin detected
test_check_service: Starts services
checktokenmembership: Checks user token with CheckTokenMembership call
open_winlogon_process: Trying to open winlogon process