Managed XDR

mspub.exe — malware analysis report

File info

Filename
mspub.exe
File type
PE32 executable (GUI) Intel 80386, for MS Windows
File size
9.7 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
7ba107378f12c57f9bc29404aabc829e701f4e7f
SHA256
f1e83e7beb350727adc861a07f6847749ad7b038daf9d22564838ab39e0e7c17
MD5
c6bca286f90e9dbb38f2a93206167bd9

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
has_pdb: This executable file has a PDB path