Managed XDR

e-root-samples-malware...b9048087d060dec50a58a0 — malware analysis report

File info

Filename
e-root-samples-malwareingestion-2024.08-2024-08-16-26b8c76e0d73833a67316e5857be6f857580165896b9048087d060dec50a58a0
File type
PE32 executable (GUI) Intel 80386, for MS Windows
File size
160.5 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
d29ba87e0eae95e0747b3bae3948c975fa9c7240
SHA256
26b8c76e0d73833a67316e5857be6f857580165896b9048087d060dec50a58a0
MD5
a00a57e179640d79f9c39284902b6e09

Signatures

Persistence

T1574 dropper_dll: Creates DLL, which is then loaded into the process

Privilege Escalation

T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Other

yara_rules: Static rules
creates_exe: Creates executable files in the file system
create_rpc_bindings: Creates RPC connection