Managed XDR

manualupdate.exe — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
manualupdate.exe
Тип файла
PE32 executable (GUI) Intel 80386, for MS Windows
Размер файла
8.4 MB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
18180c5e2d37a208aeac0f585f8c80017c1d31da
SHA256
1383bcb7262510e30aa18bceb7c4776ea23d78bce51e4b9f84b67d5480eb06c5
MD5
3ad7aa81fef5637111e3869e628f0f4c

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antivm_queries_computername: Retrieves the computer name

Other

yara_rules: Static rules
non_quadratic_icon: Icon is not square
no_graphical_activity: No graphic activity
has_pdb: This executable file has a PDB path
message_box: Displays a message
checktokenmembership: Checks user token with CheckTokenMembership call
pe_overlay: PE file contains overlay
static_low_entropy: Very low entropy of a file
valid_authenticode: The digital signature has been verified