Managed XDR

2_38331.zip — malware analysis report

File info

Filename
2_38331.zip
File type
Zip archive data, at least v1.0 to extract
File size
461 Bytes
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
6a3a66e2fa4d4e55cd64ae87691abc7551d94afa
SHA256
f9c196fec2ed4eef43b5d2e026d3adf3e536e543dea1168e30b57cd004911558
MD5
10dc7db591afd8f6f595c94a909b921f

Signatures

Execution

T1204.002 mimics_extension: Attempts to mimic the file extension
T1203 suspicious_msapp: Suspicious execution of Microsoft Application (possible exploitation)

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1036 mimics_extension: Attempts to mimic the file extension
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
checktokenmembership: Checks user token with CheckTokenMembership call