Managed XDR

vtdl_67wg9enq — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl_67wg9enq
Тип файла
Zip archive data, at least v2.0 to extract
Размер файла
3.6 MB
Первое обнаружение
Последнее обнаружение

Окружение

w10/x64 en

Хеши

SHA1
ce38a76333160292fecc020ec9dd2adb395d6faf
SHA256
9c0409a201ed4c010bb6a547f9b4d399fb7d5d1022ff18aa42d7020c85c8edea
MD5
c44edfa6820c83d7c8469dbd76750ea7

Сигнатуры

Privilege Escalation

T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.001 antivm_generic_bios: Checks the BIOS version, possibly for anti-virtualization
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antivm_generic_bios: Checks the BIOS version, possibly for anti-virtualization
T1497.001 antivm_queries_computername: Retrieves the computer name

Other

yara_rules: Static rules
static_pe_anomaly: The PE file structure contains anomalies
dotnet_suspicious_resources_names: Dotnet program has suspicious resources names
dotnet_suspicious_module_name: Dotnet program has suspicious module name
dotnet_antimetadata_analysis: Dotnet program has anti-analysis tricks
dotnet_import_unmanaged_code: Dotnet program statically imports unmanaged functions/modules
dotnet_obfuscated: Dotnet program is potentially obfuscated
test_check_service: Starts services
dotnet_suspicious_entrypoint: Dotnet program has suspicious entrypoint