Managed XDR

8e712a78dba7844e0b61ed...835c038defc0ada6en.exe — malware analysis report

File info

Filename
8e712a78dba7844e0b61edcae3a363f99d0d3e3c958143a835c038defc0ada6en.exe
File type
PE32 executable (GUI) Intel 80386, for MS Windows
File size
341.5 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
964ad877e515039f4ab0a31fba366576de1a2270
SHA256
a1b96ca3d61ba62fb09bec06afc4df1ed1c0ba8fbae040eb3531db6076e0c9a1
MD5
23c78847a97cdb1cda39588c91cb6229

Signatures

Privilege Escalation

T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
dead_host: Connects to IP addresses that do not respond to requests
no_graphical_activity: No graphic activity
has_pdb: This executable file has a PDB path
get_policy_info: Retrieves information about a Policy object
suspicious_network_port: Performs TCP or UDP request to non-standard port
pe_overlay: PE file contains overlay