Managed XDR

sockstest.exe — malware analysis report

File info

Filename
sockstest.exe
File type
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size
60.5 KB
First seen
Last seen

Environment

w10/x86 en

Hashes

SHA1
b62058738bc7e87553ae3b3d42d3cbc805e62dbe
SHA256
3f6069118ea7b598e1935b5aed56b74c124f13d3d880fd7d78d774e6c19d1fe6
MD5
4b23c98653874382dbbe4bccec981eeb

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antivm_queries_computername: Retrieves the computer name

Other

yara_rules: Static rules
process_crashed: One of the processes has failed