Managed XDR

vtdl_fig50yl3 — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl_fig50yl3
Тип файла
RAR archive data, v4, os: Win32
Размер файла
333.6 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
0d7cda36de1722464201bb93888708c8aa421b67
SHA256
62997ecbbb2720245ae9d35ca942e94ee109f3548114b464eb2475ad2b4ff4b4
MD5
081690a3ae6cd42457cc40362386b2a6

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1057 process_interest: Enumerates processes

Other

yara_rules: Static rules
static_pe_anomaly: The PE file structure contains anomalies
has_pdb: This executable file has a PDB path
origin_langid: Unconventional language of the executable file