Managed XDR

file.exe — malware analysis report

File info

Filename
file.exe
File type
PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed
File size
59 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
4c024f7870d53e43ac2af1593649e7a04a8e1820
SHA256
a1d276d3e2c0831365cdeb50ce6ec0c366f5b5550c4eaca3b53376f87c5e3ecf
MD5
ae42b6205be573129149f6cf572c6aff

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1070.004 deletes_self: Moves to different location or removes the original executable file
T1027.002 unnamed_memory_regions_contains_pe: One or several unnamed memory regions are PE files
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1027.002 packer_upx: The executable file is compressed using UPX
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
creates_exe: Creates executable files in the file system
executes_dropped_exe: Executes dropped exe files