Managed XDR

vtdl_1790225397_5py96xcs — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl_1790225397_5py96xcs
Тип файла
PE32 executable (GUI) Intel 80386, for MS Windows
Размер файла
196 KB
Первое обнаружение
Последнее обнаружение

Окружение

w10/x64 en

Хеши

SHA1
48f42536f4fc7f443f3b913dea7532efcd3a7ea5
SHA256
26f8d13cd450d32da6bc76301e6c666b78e0cd71dc24837633e100c0a0b3f869
MD5
a44cf26d09e74d8ae08476e4447e34e6

Сигнатуры

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1480 system_default_lang_id_present: Checks the system language
T1134 opens_process_token: Opens the access token associated with a process

Command and Control

T1071.001 network_http: Performs HTTP requests

Other

suricata_alert: Malicious traffic detected
has_pdb: This executable file has a PDB path
origin_langid: Unconventional language of the executable file
suspicious_network_port: Performs TCP or UDP request to non-standard port