Managed XDR

dfc55533259a9871ed86c07ace1415cd.virus (Tinba) — malware analysis report

File info

Filename
dfc55533259a9871ed86c07ace1415cd.virus
File type
PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed
File size
59 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
b42477114574d61bd2b6a1f934a27bb36d04a695
SHA256
b3639131d9add5f4586093712a42b8ff746013e1c406a32badff8d00a79b8064
MD5
dfc55533259a9871ed86c07ace1415cd

Malwares

  • Tinba

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1070.004 deletes_self: Moves to different location or removes the original executable file
T1027.002 unnamed_memory_regions_contains_pe: One or several unnamed memory regions are PE files
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1027.002 packer_upx: The executable file is compressed using UPX
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
creates_exe: Creates executable files in the file system
executes_dropped_exe: Executes dropped exe files

Related reports