Managed XDR
Group-IB MDP Report
File info
Filename: ovfile.exe
File Type: PE32 executable (GUI) Intel 80386, for MS Windows
File Size: 300 KB
Env info
win7/x86 en
Hashes
SHA1: 63a9355ebabf0f6de75614d0d92c55bd8376b4c4
SHA256: c028e8af4754352f00b217de8b3111f1018030249976c3b1264c688e7d41ab9a
MD5: 40121efb9d311cdeab153afb07da60ef
Malwares
IcedID
Signatures
Privilege Escalation
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
Defense Evasion
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
Command and Control
T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp
Other
yara_rules: Static rules
dns_without_resolve: DNS query without a response
no_graphical_activity: No graphic activity
has_pdb: This executable file has a PDB path
Managed XDR