Managed XDR

g-2020-samples-samples...5ea9c6b98d94fda930.vir — malware analysis report

File info

Filename
g-2020-samples-samples-exe32-a-virussign.com_a1a5f3732426675ea9c6b98d94fda930.vir
File type
PE32 executable (GUI) Intel 80386, for MS Windows
File size
463.8 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
78899b5c79a2e131c12939228649f35204fbfcd1
SHA256
ded7beedd1648c4a4c79ec2c7cca25e48f1882385e2ef0f83f1ab6c0428b910e
MD5
a1a5f3732426675ea9c6b98d94fda930

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
process_crashed: One of the processes has failed
no_graphical_activity: No graphic activity
pe_overlay: PE file contains overlay