Managed XDR

fc62ce2fde5e80d4c60b582645b619e6.virus (OlympicDestroyer) — malware analysis report

File info

Filename
fc62ce2fde5e80d4c60b582645b619e6.virus
File type
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
File size
789.5 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
0360c7a3a557421c43c466e5fd75626007d8dd10
SHA256
419cb7457963125a304dbfe0f1b5902ca6afe2e79188d6131dcd1c19d2c62c8b
MD5
fc62ce2fde5e80d4c60b582645b619e6

Malwares

  • OlympicDestroyer

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1480 system_default_lang_id_present: Checks the system language

Credential Access

T1552 cookie_files: Accesses cookie files
T1555.003 cookie_files: Accesses cookie files

Command and Control

T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp
T1071.001 wininet_https: Performs HTTP/HTTPS requests using WinInet

Other

yara_rules: Static rules
dns_without_resolve: DNS query without a response
no_graphical_activity: No graphic activity
create_rpc_bindings: Creates RPC connection
has_pdb: This executable file has a PDB path
origin_langid: Unconventional language of the executable file
get_policy_info: Retrieves information about a Policy object

Related reports