Managed XDR

scanpst.exe — malware analysis report

File info

Filename
scanpst.exe
File type
PE32 executable (GUI) Intel 80386, for MS Windows
File size
596.5 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
cd003a0fc629bf62084772e2d9860b7e535fd3e4
SHA256
f7f3e36f751474bd4c0028b17de425dd7d5cc8ecd0e620e2fdebad9f185b829a
MD5
8fdc66291e189e2a88f5e03d2b531ffd

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
has_pdb: This executable file has a PDB path