Managed XDR

wow.exe (Tinba) — malware analysis report

File info

Filename
wow.exe
File type
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
File size
13.6 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
1d655968f54fbcf99a027fe6cc1d9e1c08504ea8
SHA256
2f2ab91622e1855535ca47fe70d73ac9e895af310f86caba6e8e8ab17f219c92
MD5
c2c8bf305cf6dffde3e22645deb82453

Malwares

  • Tinba

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1562 dep_disable: Disables DEP
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
unnamed_region_exception_handler: Creates an exception handler in an unnamed region
no_graphical_activity: No graphic activity
message_box: Displays a message
pe_overlay: PE file contains overlay

Related reports