Managed XDR

vtdl_vwd24jmy (Thanos, AsyncRAT) — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl_vwd24jmy
Тип файла
RAR archive data, v5
Размер файла
278.1 KB
Первое обнаружение
Последнее обнаружение

Окружение

w10/x64 en

Хеши

SHA1
3d037f59de597de482b558cacdb4fa700197ab20
SHA256
411e7807a527fd69fbd3bbc229d71947a21be7b1d8cc6f4793df88b54607887e
MD5
2c604437fa06dac31e596e4fccf2042c

Вредоносное ПО

  • Thanos
  • AsyncRAT

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.001 antivm_disk_size: Checks the amount of free disk space
T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antivm_disk_size: Checks the amount of free disk space
T1497.001 antivm_queries_computername: Retrieves the computer name

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
has_pdb: This executable file has a PDB path
dotnet_suspicious_module_name: Dotnet program has suspicious module name
dotnet_import_unmanaged_code: Dotnet program statically imports unmanaged functions/modules
break_limit_exceeded: Warning: function calls limit has been exceeded
dotnet_obfuscated: Dotnet program is potentially obfuscated
checktokenmembership: Checks user token with CheckTokenMembership call
pe_overlay: PE file contains overlay
dotnet_suspicious_entrypoint: Dotnet program has suspicious entrypoint
dotnet_downloader_possible_network_problem: Dotnet program possibly has network problem

Похожие отчёты