Managed XDR

application_client.exe — malware analysis report

File info

Filename
application_client.exe
File type
PE32 executable (GUI) Intel 80386, for MS Windows
File size
106.5 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
8cf6abd45f4eb9a6850276291b0686526dc2a87e
SHA256
7829a9296623632f9929e44d73f9c64d27aaaba3d993d999a2b05a33107f5a7b
MD5
9ccdd386181208ca05b45195919041e7

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Other

yara_rules: Static rules
dead_host: Connects to IP addresses that do not respond to requests
no_graphical_activity: No graphic activity