Managed XDR

vtdl_qkvl9_jw — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl_qkvl9_jw
Тип файла
SMTP mail, ASCII text, with CRLF line terminators
Размер файла
145.6 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
5e20817a95a5d965afbcc25d086d84955cecb89d
SHA256
899a3a08fa61368bae8eccc9ee8bee7eabf9147f19ef0ec116cfd057ee935b90
MD5
d55adb442707e2105becb448d427d564

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Command and Control

T1071.001 network_http: Performs HTTP requests

Other

yara_rules: Static rules
creates_exe: Creates executable files in the file system
create_process_failed: Could not start the process
creates_in_programdata: Creates files in the ProgramData directory
suricata_alert: Malicious traffic detected