Managed XDR

php4pvmyf — malware analysis report

File info

Filename
php4pvmyf
File type
PE32 executable (GUI) Intel 80386, for MS Windows
File size
373 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
f0e9a119f0f04913a390bc6ff1df6aef59846c99
SHA256
39cac7faf62eb004e7616e8e32cb98f61e5f5098be970bb4c342d4200a0b2aad
MD5
9d396a18e1a8388711eb8b12864f2b42

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
origin_langid: Unconventional language of the executable file