Managed XDR

ois.exe — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
ois.exe
Тип файла
PE32 executable (GUI) Intel 80386, for MS Windows
Размер файла
427.2 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
27fa7ef74ae8c5ac845e02f75641cf40fde786a5
SHA256
54f1116af741c856feb9a987207f56d7fb678fc97d4e2a2e3d2caa0b73453e9a
MD5
215783b491770d914b7290d6b69c1888

Сигнатуры

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1036.001 invalid_authenticode: Digital signature of the executable file has failed the verification
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
has_pdb: This executable file has a PDB path
pe_overlay: PE file contains overlay