Managed XDR

9a7f8aadd36662683ef036a151983bb3.exe — malware analysis report

File info

Filename
9a7f8aadd36662683ef036a151983bb3.exe
File type
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
File size
47.1 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
53a8d260f09bcf1b8a6913594eab4f2b42c6ea2b
SHA256
11dd2d73097dc720e34f459d42789755c799e62010db448bcdd715fb48fb7e20
MD5
9a7f8aadd36662683ef036a151983bb3

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1480 system_default_lang_id_present: Checks the system language
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files

Command and Control

T1071.001 network_http: Performs HTTP requests
T1071.001 wininet_https: Performs HTTP/HTTPS requests using WinInet

Other

yara_rules: Static rules
networkdyndns_checkip: Connects to a Dynamic DNS domain
dns_without_resolve: DNS query without a response
no_graphical_activity: No graphic activity
creates_suspended_process: Creates suspended process
message_box: Displays a message
get_policy_info: Retrieves information about a Policy object
creates_in_programdata: Creates files in the ProgramData directory
pe_overlay: PE file contains overlay
suricata_alert: Malicious traffic detected