Managed XDR

c-users-user-appdata-local-temp-bit82d2.tmp — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
c-users-user-appdata-local-temp-bit82d2.tmp
Тип файла
PE32 executable (GUI) Intel 80386, for MS Windows
Размер файла
147 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
57a37fa8bf06bf92c36c612926d8077a06299915
SHA256
9f69a43241789f9f9ff3959444ce57fbe3c9ca0324d9a09f97926957104f984b
MD5
d0d9dfd297f71221b37662e43597e516

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
process_crashed: One of the processes has failed
no_graphical_activity: No graphic activity
test_check_service: Starts services