Managed XDR

vtdl_s10wjzrv — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl_s10wjzrv
Тип файла
PE32 executable (GUI) Intel 80386, for MS Windows
Размер файла
276 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
7047722f5d8d23a670d11e6b30193d65bbe0d1ba
SHA256
a131b61e0a8dd6db0f99638208e667774ef6bb1692557a235ec43cacd2f91ff3
MD5
4c44d6b1d988b9864820443577fe9440

Сигнатуры

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
process_crashed: One of the processes has failed
no_graphical_activity: No graphic activity