Managed XDR

c-users-leroy-appdata-...cf43e8a8-uqedqotk3.exe (Hupigon, IcedID) — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
c-users-leroy-appdata-roaming-63cf865f-6a5a-06e9-3bb7-3262cf43e8a8-uqedqotk3.exe
Тип файла
PE32 executable (GUI) Intel 80386, for MS Windows
Размер файла
796 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
df1f39ca3715bf8a6e9ba055e2f216b0a60ee28a
SHA256
b873fd178ceb662d98cc46f587362139c763a2c328d951ed5d53b7b13e49c827
MD5
11fa98be772a0eeefd9da6ac562dd04f

Вредоносное ПО

  • Hupigon
  • IcedID

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Command and Control

T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp

Other

yara_rules: Static rules
icedid_downloader: Detected downloader of banker IcedID
dns_tld_pw: Connects to TLD .PW, possibly malware
dns_without_resolve: DNS query without a response
no_graphical_activity: No graphic activity
has_pdb: This executable file has a PDB path
suricata_alert: Malicious traffic detected

Похожие отчёты