Managed XDR

wrf-00f4d079-220c-4690...bb36-620ea1af377d-.tmp — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
wrf-00f4d079-220c-4690-bb36-620ea1af377d-.tmp
Тип файла
Composite Document File V2 Document, Cannot read section info
Размер файла
64 KB
Первое обнаружение
Последнее обнаружение

Окружение

winxp/x86 en

Хеши

SHA1
e50c6949c99cef545ecab0fd6efab93ea3729b9c
SHA256
c72068fa9e61ab29ff9d7e6e1b1e6a917c0169692d1379a7e309eb0cabf72b77
MD5
4396fde9432c5f6b2923d67593f41ddf

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
creates_in_programdata: Creates files in the ProgramData directory