Managed XDR

vtdl_hplpsyvr — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl_hplpsyvr
Тип файла
Microsoft Word 2007+
Размер файла
10.1 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
9a5b9ffd2a81c3617de26f38420e2a09ff50a79a
SHA256
f3f4103d56bdde893f4b8bae4237964e8dd816571769ff5a70b1cd7a93876bd8
MD5
7e8339891fd1d5c88c976f32b8eab516

Сигнатуры

Execution

T1559 suricata_alert: Malicious traffic detected
T1559 creates_doc: Creates (office) documents in the file system
T1559 unexpected_exception: Unexpected exception
T1559 process_crashed: One of the processes has failed
T1559 get_sid_domain: Get user's SID
T1559 test_check_service: Starts services
T1559 create_rpc_bindings: Creates RPC connection

Privilege Escalation

T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges

Defense Evasion

T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges

Discovery

T1083 checks_recent_files: Attempt to check recently opened files through registry
T1497.001 antivm_queries_computername: Retrieves the computer name

Command and Control

T1071.001 network_http: Performs HTTP requests
T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp
T1071.001 wininet_https: Performs HTTP/HTTPS requests using WinInet

Other

yara_rules: Static rules
get_memory_status: Gets information about the virtual and physical memory of the system
get_username: Gets username