Managed XDR

ois.exe — malware analysis report

File info

Filename
ois.exe
File type
PE32 executable (GUI) Intel 80386, for MS Windows
File size
427.2 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
0c9660b9d533d34ba1e72739aac9838ad9a82508
SHA256
fa5858ecc42b2a45492effad9dcc1e03140773bdac41dae945b9bce3fc463eed
MD5
abe9b4e3bb4ea58d356d1ce6249fe713

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1036.001 invalid_authenticode: Digital signature of the executable file has failed the verification
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
has_pdb: This executable file has a PDB path
pe_overlay: PE file contains overlay