Managed XDR

privateserverclientbuilder.exe — malware analysis report

File info

Filename
privateserverclientbuilder.exe
File type
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
File size
1.4 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
a684e74a1064fa49ee38f776ea3fd72105e75685
SHA256
035c4d67867b6230ad5109d29f5c857611c586788db31552e67a39bd9d2d08be
MD5
233a26783785fdc317ab7df016258415

Signatures

Persistence

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup

Privilege Escalation

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1564.001 stealth_file: Creates hidden or system files
T1480 system_default_lang_id_present: Checks the system language
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
dead_host: Connects to IP addresses that do not respond to requests
message_box: Displays a message
creates_in_programdata: Creates files in the ProgramData directory
suspicious_network_port: Performs TCP or UDP request to non-standard port
pe_overlay: PE file contains overlay