Managed XDR

vtdl_lw_3ewln (BlackMatter, Lockbit) — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl_lw_3ewln
Тип файла
PE32+ executable (GUI) x86-64, for MS Windows
Размер файла
1.5 MB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x64 en

Хеши

SHA1
de684f1973d5c347758515b1b1db09d841177171
SHA256
081258ce17f6cc73f510d43d8d730735294b9754afd3c3c56de4ec5c1bb7c53c
MD5
e3119763a16b4f7a363d5a33ced2c7ec

Вредоносное ПО

  • BlackMatter
  • Lockbit

Сигнатуры

Execution

T1204.002 mimics_extension: Attempts to mimic the file extension

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1036 mimics_extension: Attempts to mimic the file extension
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
only_exec_in_archive: The archive contains only an executable file
no_graphical_activity: No graphic activity
has_pdb: This executable file has a PDB path
pe_overlay: PE file contains overlay

Похожие отчёты