Managed XDR

vtdl_jbspi0au — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl_jbspi0au
Тип файла
PE32 executable (GUI) Intel 80386, for MS Windows
Размер файла
611 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
a237ff96e3c0309b286f8e6a91cea92c56669461
SHA256
12b502a58c7ab4faf071daea0bde847c301c2c6e76c5e0ac63cd0edc63de2320
MD5
6a8bab17df54a9f1395296a448aab1f7

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.001 antivm_sandboxie: Attempts to detect Sandboxie
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antivm_sandboxie: Attempts to detect Sandboxie

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
no_graphical_activity: No graphic activity