Managed XDR

0f84125bc742150f9ff6a588f62e470d.virus (Upatre) — malware analysis report

File info

Filename
0f84125bc742150f9ff6a588f62e470d.virus
File type
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
File size
51.2 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
ca396a62e8d5230d2d15743ac6c0bf7cf1a47522
SHA256
8a991f3a1dbb872a892e18730a8dc07f75ae12b056130c9a103ae55f6c67cd19
MD5
0f84125bc742150f9ff6a588f62e470d

Malwares

  • Upatre

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_polymorphic: Creates a modified copy of itself
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1070 stealth_window: A process created a hidden window

Discovery

T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1497.001 antivm_queries_computername: Retrieves the computer name

Other

yara_rules: Static rules
static_pe_anomaly: The PE file structure contains anomalies
creates_exe: Creates executable files in the file system
executes_dropped_exe: Executes dropped exe files
no_graphical_activity: No graphic activity
get_policy_info: Retrieves information about a Policy object
pe_overlay: PE file contains overlay

Related reports