Managed XDR

unknownspf.exe — malware analysis report

File info

Filename
unknownspf.exe
File type
PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows
File size
268.2 KB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
b92fc98018c08baa0cfed286cd548a928d9d2601
SHA256
d9a953fc2b65552b2c6089ca9c76220199f2fcdb8692822c836f336a86fa559a
MD5
623bfd45131585b1780ca829d8b2d0e9

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1070 stealth_window: A process created a hidden window
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
static_pe_anomaly: The PE file structure contains anomalies
no_graphical_activity: No graphic activity
require_administrator: Requests administrator privileges
dotnet_import_unmanaged_code: Dotnet program statically imports unmanaged functions/modules
pe_overlay: PE file contains overlay
dotnet_downloader_possible_network_problem: Dotnet program possibly has network problem