Managed XDR

client.exe (Tinba) — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
client.exe
Тип файла
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
Размер файла
876.5 KB
Первое обнаружение
Последнее обнаружение

Окружение

w10/x86 en

Хеши

SHA1
39d35451082b41688518670edc043b3d53ad5c91
SHA256
2435082497f6dabe919f342165a328d735769afca2236bfe0ee0c0585cf9e366
MD5
0e48c929093f0eebbc59c7cc28a3d4b8

Вредоносное ПО

  • Tinba

Сигнатуры

Execution

T1047 has_wmi: Executes one or several WMI requests

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
dotnet_suspicious_resources_names: Dotnet program has suspicious resources names
create_rpc_bindings: Creates RPC connection
require_administrator: Requests administrator privileges
dotnet_embeded_dependencies_by_costura: Dotnet program has embedded dependencies by Costura
has_pdb: This executable file has a PDB path
dotnet_downloader_possible_network_problem: Dotnet program possibly has network problem

Похожие отчёты