Managed XDR

vtdl_23aewel_ — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl_23aewel_
Тип файла
Rich Text Format data, version 1, ANSI
Размер файла
1.1 MB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
5f58a4c551bb57761e875c60b3181c3c0068d8b5
SHA256
2283dcec06c9d9e43d17af0597a2160b2097fdd1d771170829ebec5d639dbbd1
MD5
5c46707e88bff8cef36f4ca0fc3dbd70

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents

Other

yara_rules: Static rules
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card