Managed XDR

file.none.0xfffffa8004...ashington_leak.rtf.dat (Meterpreter) — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
file.none.0xfffffa80040b3260.important_ecorp_lawsuit_washington_leak.rtf.dat
Тип файла
Rich Text Format data, version 1, unknown character set
Размер файла
100.5 KB
Первое обнаружение
Последнее обнаружение

Окружение

winxp/x86 en

Хеши

SHA1
66d67bfcb25980f42b0367c995140ac6d8bb9f89
SHA256
506a4e539afe23b44d337e95afa095cb72f6586eeba039a941da6836d35ba1aa
MD5
a392f96014de9171e9758506e5857e5b

Вредоносное ПО

  • Meterpreter

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread

Other

yara_rules: Static rules
creates_in_programdata: Creates files in the ProgramData directory

Похожие отчёты