Managed XDR

g-2020-samples-samples...b51a4e500776c499b0.vir — malware analysis report

File info

Filename
g-2020-samples-samples-mzothers-1-virussign.com_13c15d8bf3fcf9b51a4e500776c499b0.vir
File type
PE32 executable (console) Intel 80386, for MS Windows
File size
12.5 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
cca52c489f869a35f31314b0ac857987a6bea423
SHA256
97f233b1bb6bda61744a78fdd6264cb67cb090a83bc45bcf2032f7d1996ad89e
MD5
13c15d8bf3fcf9b51a4e500776c499b0

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files

Command and Control

T1071.001 wininet_https: Performs HTTP/HTTPS requests using WinInet

Other

yara_rules: Static rules
shellcode_wininet: Wininet-shellcode behaviour detected
dead_host: Connects to IP addresses that do not respond to requests
create_rpc_bindings: Creates RPC connection
has_pdb: This executable file has a PDB path
get_policy_info: Retrieves information about a Policy object