Managed XDR

servertool.exe — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
servertool.exe
Тип файла
PE32+ executable (console) x86-64, for MS Windows
Размер файла
2 MB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x64 en

Хеши

SHA1
45cc36ac0f8dab75cb80388d1ea3ffdd0ecf32ba
SHA256
947a5cf7a78d6e3b5b407caa1f363c74393ee826d9bf0aa07896ba38a05f4df8
MD5
6e50c6208c46c195d96d7153e3062820

Сигнатуры

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1036.001 invalid_authenticode: Digital signature of the executable file has failed the verification
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
has_pdb: This executable file has a PDB path
pe_overlay: PE file contains overlay