Managed XDR

vtdl_a7sqazyy — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl_a7sqazyy
Тип файла
PE32 executable (GUI) Intel 80386, for MS Windows
Размер файла
9.7 MB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
4fd74612046a8f9d7846aa92240582c44f95edb0
SHA256
2e2c098afacbddb8de1b2c75169bbf3b9573559979edc7d51cde67eba71e8472
MD5
cf5679d017a2463ca340f07c70e9d608

Сигнатуры

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
has_pdb: This executable file has a PDB path