Managed XDR

d95eeae6eefe79266a9d4c24b50228d1.virus — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
d95eeae6eefe79266a9d4c24b50228d1.virus
Тип файла
PE32 executable (GUI) Intel 80386, for MS Windows
Размер файла
339 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
173138893dffde6ab76420d2ddf374bd156024ad
SHA256
e74697ff09577b3ab6ec70d74c6996263199c47a0b00e56448185a0e0f79610e
MD5
d95eeae6eefe79266a9d4c24b50228d1

Сигнатуры

Execution

T1059.001 suspicious_powershell: Creates suspicious powershell process
T1059.001 suspicious_process: Spawns a suspicious process

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process
T1055 injection_failed: The attempt to inject into a process has failed

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_process_token: Opens the access token associated with a process
T1055 injection_failed: The attempt to inject into a process has failed

Other

yara_rules: Static rules
creates_many_processes: Spawns a lot of processes (over 70)
static_pe_anomaly: The PE file structure contains anomalies
no_graphical_activity: No graphic activity
break_limit_exceeded: Warning: function calls limit has been exceeded