Managed XDR

releases-flowseal_zapr...-discord-youtube.mhtml — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
releases-flowseal_zapret-discord-youtube.mhtml
Тип файла
news or mail, ASCII text, with CRLF line terminators
Размер файла
1.6 MB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x64 en

Хеши

SHA1
4de2b83cae3a09d9ac135b23115a9fa1c7786e11
SHA256
f0f456c0eacc5fc2e453734bba1e97520fe06735675c537117c1a5357a4b30f9
MD5
9600d06d54cfc575ec58b8fb2bec0a1d

Сигнатуры

Execution

T1059.001 suspicious_powershell: Creates suspicious powershell process
T1059.001 suspicious_process: Spawns a suspicious process
T1059.001 url_cmdline: Cmdline of process contains URL
T1059.003 suspicious_batch: Suspicious batch
T1059.003 url_cmdline: Cmdline of process contains URL

Defense Evasion

T1027.002 unnamed_memory_regions: Code was executed in unnamed regions

Discovery

T1518 locates_browser: Attempts to identify where browsers are installed

Command and Control

T1102.003 references_github: Contains links to cloud services of Github (potentially for malicious payload delivery)

Impact

T1489 net_stop: Stops services through the use of net stop

Other

creates_many_processes: Spawns a lot of processes (over 70)
codepage: Checks the system code page
unexpected_exception: Unexpected exception
require_administrator: Requests administrator privileges