Managed XDR

7457067d584138618c8d5d...1767735093390119315.gz — malware analysis report

File info

Filename
7457067d584138618c8d5d213f33683440ceadf040e3bcc2b9010745854ebf6a-1767735093390119315.gz
File type
gzip compressed data
File size
2.3 MB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
703de56b507135c34bff11bb337d8e09a3a9c6e2
SHA256
3e41833d435be775dbc25b36021a1fa3f4a0b46ef40edcf43ffbcd135fd0a88d
MD5
a673233a8110011aaf43ca8fd7b89650

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_polymorphic: Creates a modified copy of itself
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497.002 antivm_usbstor: Reads information about usbdevices from regkey
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1555.004 windows_credential_manager: Acquire credentials from the Windows Credential Manager

Discovery

T1518 locates_browser: Attempts to identify where browsers are installed
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497.002 antivm_usbstor: Reads information about usbdevices from regkey

Collection

T1074.001 access_recyclebin: Manipulation with recyclebin detected

Other

creates_exe: Creates executable files in the file system
network_bind: Starts servers listening at None
creates_doc: Creates (office) documents in the file system
only_exec_in_archive: The archive contains only an executable file
suspicious_network_port: Performs TCP or UDP request to non-standard port
test_check_service: Starts services
writes_data: Writes big amount of data to disk
pe_overlay: PE file contains overlay
Managed XDR