Managed XDR

98272cada9caf84c31d70f...caee1893a7a6f63_unpack — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
98272cada9caf84c31d70fdc3705e95ef73cb4a5c507e2cf3caee1893a7a6f63_unpack
Тип файла
PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows
Размер файла
2.2 MB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x64 en

Хеши

SHA1
edb33f83c49268ef604e073d33f358b5b4da60ce
SHA256
f632dce9c6fea6d80521a00fd89bfc7dbeaeb1e66ef680159c2c4209662a5d8e
MD5
99762b33396b8128e6e72fc66a8e8939

Сигнатуры

Execution

T1047 has_wmi: Executes one or several WMI requests

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1480 system_default_lang_id_present: Checks the system language

Credential Access

T1552.001 infostealer_bitcoin: Attempts to obtain access to Bitcoin/ALTCoin wallets

Discovery

T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Impact

T1486 modifies_files: Cryptolocker indicators detected (renamed 100 or more files)
T1485 deletes_files: Removes 100 or more files from C: drive
T1486 ransomware_message: Ransomware indicators detected (possible ransom message creation)

Other

no_graphical_activity: No graphic activity
break_limit_exceeded: Warning: function calls limit has been exceeded
writes_data: Writes big amount of data to disk
pe_overlay: PE file contains overlay
yara_rules: Static rules