Managed XDR

vtdl_1741291022_h9p4a70t — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl_1741291022_h9p4a70t
Тип файла
PE32 executable (GUI) Intel 80386, for MS Windows
Размер файла
392 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
b943b34bdf9c273dbc34b0ae8b56f511f860cab9
SHA256
d7704dd6d811aa52a8b8b7c36595f7c60901f43a1ae113bb38cc6d01a6df3f87
MD5
3557a42eec37d98c47f7d9fa365ee0c1

Сигнатуры

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process
T1055 injection_failed: The attempt to inject into a process has failed

Defense Evasion

T1134 opens_process_token: Opens the access token associated with a process
T1055 injection_failed: The attempt to inject into a process has failed
T1027.002 packer_entropy: Probably contains compressed or encrypted data

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity