Managed XDR

vtdl_ldqhsguo — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl_ldqhsguo
Тип файла
SMTP mail, ASCII text, with CRLF line terminators
Размер файла
76.9 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
b127d6d6987524c10fee67dc8f4421be94fd49f9
SHA256
84dab780cadf4b0c4c59306e485b4824d89e691c11354ca7ae02e7d801d1c783
MD5
fa16e2114d5446bc24b9e72236e3b086

Сигнатуры

Defense Evasion

T1497.002 async_mouse: Watches for mouse clicks using GetAsyncKeyState to detect human activity

Discovery

T1497.002 async_mouse: Watches for mouse clicks using GetAsyncKeyState to detect human activity

Command and Control

T1102.003 references_azure: Contains links to cloud services of Azure (potentially for malicious payload delivery)

Other

yara_rules: Static rules
suspicious_pdf: PDF file with suspicious content
pdf_page: Contains only one page
create_rpc_bindings: Creates RPC connection
pdf_compressed_stream: Contains an object with compressed stream
get_sid_domain: Get user's SID
office_links: Office file contains external links
get_memory_status: Gets information about the virtual and physical memory of the system