Managed XDR

vtdl_8a1kifs0 — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl_8a1kifs0
Тип файла
MS Windows shortcut, Item id list present, ctime=Sat Oct 5 01:15:19 2024, mtime=Sat Oct 5 01:15:19 2024, atime=Sat Oct 5 01:15:19 2024, length=0, window=hide
Размер файла
1 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
3f441eec8a7630e3e14a71ded6391e24d23aa5ad
SHA256
ee4757cb049e63b57070c8ca7469b5ee4a2b45c1ac59fcd69f27bd2426d04e7c
MD5
6175b413d3a0163830588d432ec3d00a

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
no_graphical_activity: No graphic activity
creates_suspended_process: Creates suspended process