Managed XDR

airwin.exe (Hive) — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
airwin.exe
Тип файла
PE32+ executable (console) x86-64, for MS Windows
Размер файла
14.5 MB
Первое обнаружение
Последнее обнаружение

Окружение

w10/x64 en

Хеши

SHA1
6b50b2402f4edaf99e19e06ab2e8371532258365
SHA256
e7f498e3898cd41e3adcb3933ea15f2727aed189675dad329b06034f2d2dc460
MD5
4a274be2d3631b69068e6bcc976c3865

Вредоносное ПО

  • Hive

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1056.001 infostealer_keylogger: Keylogger (intercepts keystrokes)

Collection

T1056.001 infostealer_keylogger: Keylogger (intercepts keystrokes)

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
has_pdb: This executable file has a PDB path

Похожие отчёты