Managed XDR

vtdl_1761886810_lulc2n1b — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl_1761886810_lulc2n1b
Тип файла
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=11, Archive, ctime=Mon Sep 8 10:14:54 2025, mtime=Fri Oct 31 03:33:49 2025, atime=Mon Sep 8 10:14:54 2025, length=289792, window=hide
Размер файла
2.1 KB
Первое обнаружение
Последнее обнаружение

Окружение

w10/x86 en

Хеши

SHA1
07c98606789f1f130c804aa7b3fade717c0be890
SHA256
0166051f59e3c40821ce60eb566b6a10fc11ab593ba497091f018972831ee4d0
MD5
6e90714395f939a21ea31200322c94ac

Сигнатуры

Execution

T1204 suspicious_lnk: LNK file with suspicious content

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1082 recon_systeminfo: Collects system information (ipconfig, netstat, systeminfo, net)

Command and Control

T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp

Other

creates_suspended_process: Creates suspended process
writes_data: Writes big amount of data to disk
yara_rules: Static rules