Managed XDR

vtdl_ozr36l2m — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl_ozr36l2m
Тип файла
RAR archive data, v5
Размер файла
7.1 MB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x64 en

Хеши

SHA1
31d9b05e2b7665321e50603874b501d21767f69f
SHA256
fa2806150a9628551792a05a9f0da20479f0f90cf935ca6dd8bcca34a014ac2e
MD5
cac4775653476d81935ba5efcd8e6e89

Сигнатуры

Initial Access

T1192 html_urls: HTML-document downloads a file

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1552.002 infostealer_steam: Attempts to collect information about Steam account
T1552 infostealer_browser: Retrieves personal information from local Internet browsers
T1552 infostealer_ftp: Collects data from local FTP clients
T1552.001 infostealer_vpn: Collects information about installed VPN software
T1503 infostealer_browser: Retrieves personal information from local Internet browsers
T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
has_pdb: This executable file has a PDB path
many_files_in_archive: The archive contains more than 5 files