Managed XDR

cfedczfdzsc — malware analysis report

File info

Filename
cfedczfdzsc
File type
Mach-O i386 executable, flags:<NOUNDEFS|DYLDLINK|TWOLEVEL|WEAK_DEFINES|BINDS_TO_WEAK|PIE|NO_HEAP_EXECUTION>
File size
196.6 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
53753ea1b8eaa465c3558877461a9d0dd1d06f32
SHA256
7617d7da497d4c182ae2591c3164885425d7ea339eab6bbe2cf90db55b4ed98b
MD5
bcd88ab14b213a11e084fc3d23371eb0

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
creates_in_programdata: Creates files in the ProgramData directory