Managed XDR

minecraft.jar — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
minecraft.jar
Тип файла
Zip archive data, at least v2.0 to extract
Размер файла
9.7 MB
Первое обнаружение
Последнее обнаружение

Окружение

w10/x86 en

Хеши

SHA1
d1cba1060f7fab561de1bf5770b34d9124d9fb7b
SHA256
fa4f4afbcfbc3085e026bceffb8a9c04d0f27a9cd3ae4a3f1a38ba0f8a2c25a8
MD5
5408b96cfe6fee0cddc94e49b4972cf3

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 unnamed_memory_regions_contains_pe: One or several unnamed memory regions are PE files
T1222 icacls: May obtain or change Discretionary access control lists (DACLs)
T1497.001 antivm_disk_size: Checks the amount of free disk space
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antivm_disk_size: Checks the amount of free disk space

Command and Control

T1071.001 network_http: Performs HTTP requests

Other

yara_rules: Static rules
accesses_mailslot: Performs a Mailslot ping, possibly used to get Domain Controller information
creates_exe: Creates executable files in the file system
create_process_failed: Could not start the process
create_rpc_bindings: Creates RPC connection
creates_suspended_process: Creates suspended process
creates_in_programdata: Creates files in the ProgramData directory
writes_data: Writes big amount of data to disk
suricata_alert: Malicious traffic detected