Managed XDR

reagent.dll — malware analysis report

File info

Filename
reagent.dll
File type
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
File size
520 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
ac10f4f61cae7994c1505c4b2b476902bcb023c2
SHA256
7e247ffd597664597d0335031300a5efeb1f0f4c13dcd1f98af5b3865e14f318
MD5
914a0c955691d9b245b2e45efd90d65b

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
static_pe_anomaly: The PE file structure contains anomalies