Managed XDR

85b3c307dc5456a515977ce7b4ce4c40.bin (Tinba) — malware analysis report

File info

Filename
85b3c307dc5456a515977ce7b4ce4c40.bin
File type
SMTP mail, UTF-8 Unicode text
File size
61 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
dd7a6a14b2d37356f8018b1a10f5002f752feca1
SHA256
53de90b5d1e0b49453f6f2943022dd59540b680c446f64ab0a6ca4e751b737f4
MD5
85b3c307dc5456a515977ce7b4ce4c40

Malwares

  • Tinba

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1480 system_default_lang_id_present: Checks the system language
T1027.002 packer_vb: The executable file is packed using VB
T1027.002 packer_entropy: Probably contains compressed or encrypted data

Other

yara_rules: Static rules
creates_exe: Creates executable files in the file system
create_process_failed: Could not start the process
unexpected_exception: Unexpected exception
no_graphical_activity: No graphic activity
error_drawtext: An error occured while executing the file

Related reports