Managed XDR

c-windows-syswow64-sggtjbc.dll (Symmi) — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
c-windows-syswow64-sggtjbc.dll
Тип файла
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Размер файла
42 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
a49ef5ae146c5755350000d9aafe412d2e10cc47
SHA256
08b6fbff08d40592f1536ec30f813e4292e08c4efe13d77993e6407f1e061f0a
MD5
8cbef401d764976e776ba478c860df3c

Вредоносное ПО

  • Symmi

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
message_box: Displays a message
error_drawtext: An error occured while executing the file

Похожие отчёты