Managed XDR

anon.exe — malware analysis report

File info

Filename
anon.exe
File type
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
File size
2.6 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
09083cf6021e5edfa74abc79e11cde4e66f1da2f
SHA256
7e607ca577344a8fcc96187bddb6b2362a0fac81288d9ff05b92e989ee09b2a9
MD5
25689b777f692df67c23f47dd36f3814

Signatures

Execution

T1059.007 bad_js: Suspicious Javascript file

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1480 system_default_lang_id_present: Checks the system language
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1552 infostealer_browser: Retrieves personal information from local Internet browsers
T1503 infostealer_browser: Retrieves personal information from local Internet browsers
T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files

Impact

T1490 vssadmin_delete_shadows: Attempt to delete volume shadow copies
T1486 modifies_files2: Cryptolocker indicators detected (50 or more files are modified)
T1565.001 overwrites_firefox_settings: Modifies Mozilla Firefox settings

Other

yara_rules: Static rules
ransomware_shadowcopy: Removes volume shadow copies
creates_exe: Creates executable files in the file system
no_graphical_activity: No graphic activity
test_check_service: Starts services