Managed XDR

c-users-user-appdata-l...ntact-phone-number.bat — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
c-users-user-appdata-local-temp-ksjbaj5t.pr4-individual-list-information-for-each-member-contact-phone-number.bat
Тип файла
Little-endian UTF-16 Unicode text, with very long lines, with no line terminators
Размер файла
512.1 KB
Первое обнаружение
Последнее обнаружение

Окружение

w10/x64 en

Хеши

SHA1
a31192fc11a010bb5bc00b85e9896a1b58e7eb0f
SHA256
59e2379f86f4011267062ac7705670d7a3e262b3a15507bda1da753852dd3bd7
MD5
092816d7f660453c68394366542895cb

Сигнатуры

Resource Development

T1608.005 contacts_url_shortener: Connects to url shortening services

Execution

T1059.001 suspicious_powershell: Creates suspicious powershell process
T1059.001 suspicious_process: Spawns a suspicious process
T1059.001 url_cmdline: Cmdline of process contains URL
T1059.003 suspicious_batch: Suspicious batch
T1059.003 url_cmdline: Cmdline of process contains URL

Defense Evasion

T1497.003 antisandbox_idletime: Detects Windows Idle Time to determine the uptime

Discovery

T1497.003 antisandbox_idletime: Detects Windows Idle Time to determine the uptime
T1518 locates_browser: Attempts to identify where browsers are installed

Other

network_powershell: Powershell process network connection detected
no_graphical_activity: No graphic activity
creates_suspended_process: Creates suspended process
test_check_service: Starts services
suricata_alert: Malicious traffic detected