Managed XDR

vtdl_fpvsikbx — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl_fpvsikbx
Тип файла
RAR archive data, v4, os: Win32
Размер файла
4.3 MB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
7f8f958bb60484cec8679910f741874ce83cbe48
SHA256
80c2d847791279c44dfb85249c9837d4831a964e3d058a31a032a67b9efea94a
MD5
6294d2077865e2be521b9867238773d3

Сигнатуры

Persistence

T1574 dropper_dll: Creates DLL, which is then loaded into the process

Privilege Escalation

T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1027.002 nsis_archive: One of the packages is NSIS archive
T1480 system_default_lang_id_present: Checks the system language
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1082 fingerprint_to_file: Collects data about system and user and writes it to a text file

Other

yara_rules: Static rules
valid_authenticode: The digital signature has been verified
require_administrator: Requests administrator privileges
creates_exe: Creates executable files in the file system
origin_langid: Unconventional language of the executable file
checktokenmembership: Checks user token with CheckTokenMembership call
pe_overlay: PE file contains overlay