Managed XDR

vtdl_4zt3n_lo — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl_4zt3n_lo
Тип файла
MS Windows shortcut, Item id list present, ctime=Thu Oct 10 08:55:03 2024, mtime=Thu Oct 10 08:55:03 2024, atime=Thu Oct 10 08:55:03 2024, length=0, window=hide
Размер файла
1.1 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
24767251e08109b53439f8fdd738e79733790a88
SHA256
51ecb83f09c3f224b6abc891cc35996505d3e6e08cb6e8f7bd6dedc6d2f026a4
MD5
f76791c58fb96f12e66038a8543b08c4

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process