Managed XDR

79802d6a6be8433720857d...1fea50ff683c13_new.exe (ALPHV) — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
79802d6a6be8433720857d2b53b46f8011ec734a237aae1c3c1fea50ff683c13_new.exe
Тип файла
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
Размер файла
2.9 MB
Первое обнаружение
Последнее обнаружение

Окружение

w10/x64 en

Хеши

SHA1
bf44baba54b76c334e5f95ba2f634d3784c6b960
SHA256
5cbe9369b6cfa3662d5c417a6787f107fc1a9eb2ef686de675323382fefec2ca
MD5
1671eef32b4319f7f6c9da6f4940bf11

Вредоносное ПО

  • ALPHV

Сигнатуры

Execution

T1059.007 bad_js: Suspicious Javascript file

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1555.004 windows_credential_manager: Acquire credentials from the Windows Credential Manager

Discovery

T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization

Other

yara_rules: Static rules
modifies_certs: Attempts to generate or modify system certificates
suspicious_network_port: Performs TCP or UDP request to non-standard port
test_check_service: Starts services
writes_data: Writes big amount of data to disk
js_suspicious: Suspicious javascript

Похожие отчёты