Managed XDR

banned-20240805t113405-14257-04 — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
banned-20240805t113405-14257-04
Тип файла
SMTP mail, UTF-8 Unicode text
Размер файла
891.3 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x64 en

Хеши

SHA1
2da272b5198e14c718368944df173011d6dc03dd
SHA256
b04ce63caf610c67a8f488e68d4773a7017fcb576b0dd49985b5b3b85d401ca1
MD5
989e7a2e2b4cee351484b134fd1164ec

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1036.001 invalid_authenticode: Digital signature of the executable file has failed the verification
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antivm_queries_computername: Retrieves the computer name

Other

static_pe_anomaly: The PE file structure contains anomalies
process_crashed: One of the processes has failed
has_suspicious_pdb: This executable file has a suspicious PDB path
no_graphical_activity: No graphic activity
has_pdb: This executable file has a PDB path
dotnet_import_unmanaged_code: Dotnet program statically imports unmanaged functions/modules
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
pe_overlay: PE file contains overlay