Managed XDR

olk9677.tmp — malware analysis report

File info

Filename
olk9677.tmp
File type
data
File size
191.7 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
d9dc58d562a8fd6e65e9fc5b4750a378d0d59561
SHA256
ef160c33f18441a9b335d80a99e3b397a87f4c2e6a56c524d406d24b50b45052
MD5
ee514566c841d0b296742778b0cff484

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card