Managed XDR

vtdl__e8gquoj — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl__e8gquoj
Тип файла
MS Windows shortcut, Item id list present, ctime=Fri Sep 27 07:32:04 2024, mtime=Fri Sep 27 07:32:04 2024, atime=Fri Sep 27 07:32:04 2024, length=0, window=hide
Размер файла
1 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
b051aea6aeb5f54cf49cd7f3c588a9a7933292be
SHA256
e78af41f79a468532e7014959dfef8ea90ca42f200804e3bbbd47fc5de9453d5
MD5
aee153e17aa23351e25754e30d301a7b

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process