Managed XDR

6431a20f3835ad21462ede3d776c6bc2.virus — malware analysis report

File info

Filename
6431a20f3835ad21462ede3d776c6bc2.virus
File type
PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
File size
263.4 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
92c1db32a3edfda78f267d66714d9851d7b58d15
SHA256
ca34f98386d72f192e0c48fc3eca6f87661098b52a9a33bba66d04430b69f2fd
MD5
6431a20f3835ad21462ede3d776c6bc2

Signatures

Privilege Escalation

T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1027.002 nsis_archive: One of the packages is NSIS archive
T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1497.001 antivm_queries_computername: Retrieves the computer name

Other

yara_rules: Static rules
process_crashed: One of the processes has failed
no_graphical_activity: No graphic activity
creates_exe: Creates executable files in the file system
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
checktokenmembership: Checks user token with CheckTokenMembership call
pe_overlay: PE file contains overlay
executes_dropped_exe: Executes dropped exe files