Managed XDR

py.exe — malware analysis report

File info

Filename
py.exe
File type
PE32+ executable (console) x86-64, for MS Windows
File size
1.1 MB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
d8b4fe3f71af4b515fb080b826f07f6e8ce9a33a
SHA256
d6c731897f404c304e5fb1b3db3f36f7528c6764f33406b1d0825132f81ed1e6
MD5
6c5fac75fa26faf849b1117c472b95a2

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1497.001 antivm_queries_computername: Retrieves the computer name
T1480 system_default_lang_id_present: Checks the system language
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antivm_queries_computername: Retrieves the computer name

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
has_pdb: This executable file has a PDB path