Managed XDR

vtdl_9xiwl_gr — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl_9xiwl_gr
Тип файла
MS Windows shortcut, Item id list present, Points to a file or directory, Has Description string, Has command line arguments, Icon number=-166, Archive, ctime=Wed Oct 6 13:42:27 2021, mtime=Sun Feb 18 08:25:00 2024, atime=Wed Oct 6 13:42:27 2021, length=236544, window=hidenormalshowminimized
Размер файла
3.7 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
d3011c6d3f40bfaf4edd0a9547ca6e3bcf549963
SHA256
cbcc107d8ad951add44708f8b2cbfd6868dd8b5fe2cd52fea7acf69a23e1c72d
MD5
702b6c1945fa78fff186bfca138dbe92

Сигнатуры

Execution

T1204 suspicious_lnk: LNK file with suspicious content
T1059 suspicious_cmd_arguments: Cmd.exe uses file as a data source for the standard input stream

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process