Managed XDR

haspvlm.exe — malware analysis report

File info

Filename
haspvlm.exe
File type
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
File size
2.4 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
87cf5976b5abddb0a4573939cc4297f2097b9fea
SHA256
ad9110018e233a5f992876e0bb8b7ceb0bb46bd72f451156781dbb5dd6dd8783
MD5
4a49cba172f9822c01e982848a3c8404

Signatures

Persistence

T1574 dropper_dll: Creates DLL, which is then loaded into the process

Privilege Escalation

T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1036.001 invalid_authenticode: Digital signature of the executable file has failed the verification
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
creates_exe: Creates executable files in the file system
unexpected_exception: Unexpected exception
no_graphical_activity: No graphic activity
pe_overlay: PE file contains overlay