Managed XDR

epof4gwzwaxwm7a7.exe — malware analysis report

File info

Filename
epof4gwzwaxwm7a7.exe
File type
PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed
File size
911.4 KB
First seen
Last seen

Environment

w10/x86 en

Hashes

SHA1
eeb49347948ef1611dc3f3fab4e8564363e1c78c
SHA256
da9fdfcad624e629f13e737df4ee2846205ead19bd76eb5990a4bbea2068d1e7
MD5
9e62edf1e267aa08276719b51963221a

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1070.004 deletes_self: Moves to different location or removes the original executable file
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1027.002 packer_upx: The executable file is compressed using UPX
T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1552 cookie_files: Accesses cookie files
T1555.003 cookie_files: Accesses cookie files

Command and Control

T1071.001 network_http: Performs HTTP requests
T1071.001 wininet_openurl: Performs HTTP/HTTPS-requests using InternetOpenUrl

Other

static_pe_anomaly: The PE file structure contains anomalies
creates_exe: Creates executable files in the file system
executes_dropped_exe: Executes dropped exe files
require_administrator: Requests administrator privileges
creates_suspended_process: Creates suspended process
checktokenmembership: Checks user token with CheckTokenMembership call
writes_data: Writes big amount of data to disk
pe_overlay: PE file contains overlay
suricata_alert: Malicious traffic detected