Managed XDR

6738c4b91544f.exe — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
6738c4b91544f.exe
Тип файла
PE32+ executable (console) x86-64, for MS Windows
Размер файла
362.4 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x64 en

Хеши

SHA1
6ea21e240234f9e61ff221e2713fc52090922d70
SHA256
54a9462e0d3e36ed7cb36d8ff5529181d77646daecc26416be7c73e5a4ae8bd5
MD5
b3a5127ac5ce563ea4a8c01547bcfa55

Сигнатуры

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1036.001 invalid_authenticode: Digital signature of the executable file has failed the verification
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
pe_overlay: PE file contains overlay