Managed XDR

bareboat.exe — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
bareboat.exe
Тип файла
PE32 executable (GUI) Intel 80386, for MS Windows
Размер файла
247 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
8d0cf1b1efb88f30e6f12e6c1ace39295ecc2862
SHA256
c218f8bbb8197b3c18f168e9cc688e5c6feed944703a157f6b28420739de7860
MD5
b527019fc66668c7956bc55f83f4b40e

Сигнатуры

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antivm_queries_computername: Retrieves the computer name

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity