Managed XDR

unknown — malware analysis report

File info

Filename
unknown
File type
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
File size
3.4 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
f42e37aa934e359b5ffec3fe2ff78756537d2585
SHA256
36c9beec4b22537b6b9e2198b16611cbdba4a3e3c242255ab910866964e72162
MD5
9f40435e6578e09a07229111933adcc6

Signatures

Execution

T1059.003 cmd_ping_del: Uses cmd.exe for pausing and deletion of the original file

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1070.004 deletes_self: Moves to different location or removes the original executable file
T1070.004 cmd_ping_del: Uses cmd.exe for pausing and deletion of the original file
T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1070.004 self_removal_command: Executes command to delete itself
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1016.001 system_network_configuration_discovery: System network configuration discovery detected

Command and Control

T1095 network_icmp: Creates ICMP traffic

Other

yara_rules: Static rules
static_pe_anomaly: The PE file structure contains anomalies
no_graphical_activity: No graphic activity