Managed XDR

c-windows-installer-5fd311.msi — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
c-windows-installer-5fd311.msi
Тип файла
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Number of Characters: 0, Create Time/Date: Thu Jan 29 11:50:06 2015, Last Printed: Thu Jan 29 11:50:06 2015, Code page: 0, Title: Installation Database, Author: <manufacturer>, Subject: <product name>, Comments: This installer database contains the logic and data required to install <product name>., Keywords: Installer, MSI, Database, Template: x64;1033, Number of Pages: 500, Security: 0, Number of Words: 2, Revision Number: {C71C4206-77A1-448E-B6F2-7F53392861C9}, Last Saved Time/Date: Sat May 4 23:35:12 2024, Last Saved By: 123, Name of Creating Application: MSI Editor
Размер файла
1.3 MB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x64 en

Хеши

SHA1
e1af694288ec84cbf5f1a81a34d6e51f4dd34d72
SHA256
fd6b225d66515c35bca67bdd9e4540f6d4f6bccdf0287a6bf217f7ad68f5feef
MD5
58914639757375809d1dc3e0e8ef3608

Сигнатуры

Privilege Escalation

T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497 evasion_diskenum: Sandbox evasion using enumeration of partitions
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497 evasion_diskenum: Sandbox evasion using enumeration of partitions

Other

yara_rules: Static rules
create_rpc_bindings: Creates RPC connection
test_check_service: Starts services