Managed XDR

divxenc.exe (TeslaCrypt) — malware analysis report

File info

Filename
divxenc.exe
File type
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed
File size
444.1 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
6858aa39d29de70807e048ff19eaafbd56385378
SHA256
68e9ff9f79547c0b2ff1041d11f4a64b04112d6f486d4d75f74c8594f321f033
MD5
a9f577789751c0a3a3b43a24203560ed

Malwares

  • TeslaCrypt

Signatures

Persistence

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup

Privilege Escalation

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_polymorphic: Creates a modified copy of itself
T1027.002 packer_upx: The executable file is compressed using UPX
T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
copies_self: Creates a copy of itself
creates_exe: Creates executable files in the file system
executes_dropped_exe: Executes dropped exe files
no_graphical_activity: No graphic activity
pe_overlay: PE file contains overlay

Related reports