Managed XDR

f516578770496b3476c50fdcee2cb136.virus — malware analysis report

File info

Filename
f516578770496b3476c50fdcee2cb136.virus
File type
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
File size
14 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
18284e534369efcb5ef16770063d5a47d0b5a028
SHA256
7d229a601a84f38b46dc25f5640ed7be0dd386c2f26df84053ae2635c382d89e
MD5
f516578770496b3476c50fdcee2cb136

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_process_token: Opens the access token associated with a process
T1480 system_default_lang_id_present: Checks the system language

Other

yara_rules: Static rules