Managed XDR

13c5600ff17c2990add0581c8466a664.virus — malware analysis report

File info

Filename
13c5600ff17c2990add0581c8466a664.virus
File type
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
File size
416 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
1e26cc1a1ed6429ecfeed8055999fd3fa3c080d9
SHA256
5f1e96455f4f39a31f91166beee4368f8c74329e95b9d2a1733ad9420bbb05b2
MD5
13c5600ff17c2990add0581c8466a664

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_process_token: Opens the access token associated with a process
T1027.002 packer_aspack: Executable file is packed with ASPack
T1027.002 packer_entropy: Probably contains compressed or encrypted data

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
protector_asprotect: Executable file is protected with ASProtect