Managed XDR

banned-20240724t091421-01489-14 — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
banned-20240724t091421-01489-14
Тип файла
SMTP mail, ASCII text
Размер файла
10.1 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
37ada7e8f8b66b377637ec6078a36ab316b0e90b
SHA256
c0fe9038b156080e72113a12c9fd69a828b734fd648c192b51d9d24324db75e9
MD5
561197956cb3e0c5a52d974fc1ae891b

Сигнатуры

Initial Access

T1192 html_urls: HTML-document downloads a file

Persistence

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup

Privilege Escalation

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1562 modify_uac_prompt: Attempts to modify UAC pop-up window behavior
T1134 opens_process_token: Opens the access token associated with a process

Other

no_graphical_activity: No graphic activity