Managed XDR

scratch-zoo-2025-03-16...123c5d13ea030e456522ef — malware analysis report

File info

Filename
scratch-zoo-2025-03-16-30840c5214123c5d13ea030e456522ef
File type
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
File size
6.2 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
9116e0bbaa05e9b60f0fa5be2dfdae4f7c304ddd
SHA256
8a6e1c5055bd1185b24f7f79f4a67155d1578e96ab05a98a27e27aafd93a8910
MD5
30840c5214123c5d13ea030e456522ef

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
process_crashed: One of the processes has failed
no_graphical_activity: No graphic activity
origin_langid: Unconventional language of the executable file
test_check_service: Starts services
pe_overlay: PE file contains overlay