Managed XDR

vtdl_889v97hv — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl_889v97hv
Тип файла
MS Windows shortcut, Item id list present, Points to a file or directory, Has Description string, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, ctime=Mon Jan 1 00:00:00 1601, mtime=Mon Jan 1 00:00:00 1601, atime=Mon Jan 1 00:00:00 1601, length=0, window=
Размер файла
194 Bytes
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
a62adbb4fa4a81bec777f9b0c946059592d44698
SHA256
13e5ef1cb0f7bb8a96f89a3079446cb93a5af00510e77240e9fa0b93a4ac4423
MD5
e95c1071b4743a1a37baaf1a8c8d7164

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
no_graphical_activity: No graphic activity
creates_suspended_process: Creates suspended process