Managed XDR

cjco.exe.bin — malware analysis report

File info

Filename
cjco.exe.bin
File type
PE32+ executable (console) x86-64, for MS Windows
File size
814 KB
First seen
Last seen

Environment

win7/x64 en

Hashes

SHA1
3b7e298bdef326783ae810c40e1b8dc3a19c045c
SHA256
79bef5da8af21f97e8d4e609389c28e0646ef81a6944e329330c716e19f33c73
MD5
9d865484c6592ce9a05ef5eba490f76c

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antivm_queries_computername: Retrieves the computer name

Other

yara_rules: Static rules
has_pdb: This executable file has a PDB path