Managed XDR

atmlib.dll — malware analysis report

File info

Filename
atmlib.dll
File type
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
File size
24 KB
First seen
Last seen

Environment

win7/x64 en

Hashes

SHA1
85060b8e7595d2518b8efc6d8c5dba16647cdcb6
SHA256
deeee09ba51858e4f66d4adbb5f50e5992ece5243222b1e88622145d25495f58
MD5
7559385102d5a7fed10ee7fd79300f28

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
message_box: Displays a message