Managed XDR

a15f278540238f0308608e...55f2e965574a12_new.exe (ALPHV) — malware analysis report

File info

Filename
a15f278540238f0308608e76a76c01c60e04f5e5bbe9ffce5455f2e965574a12_new.exe
File type
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
File size
2.9 MB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
2de7a4863736c8da29519c08f26abd710c0afb17
SHA256
aed0f8adb6d23dfb613349fe6d28f3215e5831090e086391083dd3c9a2a5584d
MD5
2b839993af55c356bd34321fa6d0abdf

Malwares

  • ALPHV

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1555.004 windows_credential_manager: Acquire credentials from the Windows Credential Manager

Discovery

T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers

Other

yara_rules: Static rules
suspicious_network_port: Performs TCP or UDP request to non-standard port
test_check_service: Starts services
writes_data: Writes big amount of data to disk

Related reports