Managed XDR

vtdl_1759282242_ug8k5tgf — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl_1759282242_ug8k5tgf
Тип файла
SMTP mail, ASCII text, with CRLF line terminators
Размер файла
16.7 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
0c01a5713ca9dae4210c649e6c61e46b863276b3
SHA256
65a17d34357b0947403edea0d6af3d07d2bf991cecb90da7978f4dd6dbabeae8
MD5
a5eb672e1f6df81116cbdbc1c7682201

Сигнатуры

Execution

T1059.001 suspicious_powershell: Creates suspicious powershell process
T1059.001 suspicious_process: Spawns a suspicious process
T1204.002 mimics_extension: Attempts to mimic the file extension
T1559.001 com_exec: Execution of Win32_Process.Create COM Method

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1036 mimics_extension: Attempts to mimic the file extension
T1497 debugs_self: Creates a process and debugs it
T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497 debugs_self: Creates a process and debugs it
T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Other

modifies_certs: Attempts to generate or modify system certificates
no_graphical_activity: No graphic activity
checktokenmembership: Checks user token with CheckTokenMembership call
Managed XDR