Managed XDR

vtdl_xw2gr5_r — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl_xw2gr5_r
Тип файла
RAR archive data, v5
Размер файла
445 KB
Первое обнаружение
Последнее обнаружение

Окружение

w10/x64 en

Хеши

SHA1
7dd7cc0a9def5c3cb7748aafb344f0edaff4154c
SHA256
beac3f04ef243aaea117ba8462c2e44d67ec6248fb99a3d30fd2241bd16b8c06
MD5
b8e70e553260d2c39f8a7ad5528eb705

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antivm_queries_computername: Retrieves the computer name

Other

yara_rules: Static rules
static_pe_anomaly: The PE file structure contains anomalies
process_crashed: One of the processes has failed
no_graphical_activity: No graphic activity
has_pdb: This executable file has a PDB path
test_check_service: Starts services
dotnet_downloader_possible_network_problem: Dotnet downloader possibly has network problem