Managed XDR

client.exe (RADX RAT) — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
client.exe
Тип файла
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
Размер файла
2.5 MB
Первое обнаружение
Последнее обнаружение

Окружение

w10/x86 en

Хеши

SHA1
e5fa24978e86db9ee769426e9905746d7d75e5b9
SHA256
69edd04c4b52b8534105757d2282167ad88741dcbbc605d1eb478ce600dd1b99
MD5
9ee08d05dd6c85abf9ef7be6753da5c3

Вредоносное ПО

  • RADX RAT

Сигнатуры

Execution

T1047 has_wmi: Executes one or several WMI requests

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
dotnet_suspicious_resources_names: Dotnet program has suspicious resources names
create_rpc_bindings: Creates RPC connection
require_administrator: Requests administrator privileges
dotnet_embeded_dependencies_by_costura: Dotnet program has embedded dependencies by Costura
dotnet_import_unmanaged_code: Dotnet program statically imports unmanaged functions/modules
test_check_service: Starts services
pe_overlay: PE file contains overlay
dotnet_suspicious_entrypoint: Dotnet program has suspicious entrypoint
dotnet_downloader_possible_network_problem: Dotnet program possibly has network problem

Похожие отчёты