Managed XDR

excell.exe — malware analysis report

File info

Filename
excell.exe
File type
PE32 executable (GUI) Intel 80386, for MS Windows
File size
5.9 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
7840bf046312d5e0036ba4b9d888e704232fd4a1
SHA256
b7f75507a45b534c708abe912a8c6f4d27811f3c0c4135aa54f5340b7be8aead
MD5
ce79c9fa160df049727cf57ee68abef1

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Command and Control

T1102.003 cloud_google: Connects to cloud services of Google (potentially for malicious payload delivery)

Other

yara_rules: Static rules
modifies_certs: Attempts to generate or modify system certificates
no_graphical_activity: No graphic activity
create_rpc_bindings: Creates RPC connection
net_dumps_in_native: .Net dumps have been found in native PE
break_limit_exceeded: Warning: function calls limit has been exceeded
error_drawtext: An error occured while executing the file
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services