Managed XDR

vpreview.exe (Sodinokibi) — malware analysis report

File info

Filename
vpreview.exe
File type
PE32 executable (GUI) Intel 80386, for MS Windows
File size
337.2 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
62f9cf1d7b2e96544da8c175df0650b484521e25
SHA256
d15b51e84093f6e3193b1d68c049a6c97c81e2bbdc2296c6d0dd6b376556ef8b
MD5
2eebb520ebbda30d43a0f37cd1490b08

Malwares

  • Sodinokibi

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
process_crashed: One of the processes has failed
no_graphical_activity: No graphic activity
test_check_service: Starts services
pe_overlay: PE file contains overlay

Related reports