Managed XDR

vtdl_a9r_bq7p — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl_a9r_bq7p
Тип файла
RAR archive data, v4, os: Win32
Размер файла
291.6 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
7105444406d37f057ae5319034b4465dffb1d762
SHA256
66bbadc03f10f275970ea1e4f098ae7ed26c8094beba6bd95e6f71aeb0f42833
MD5
65e41ffda3e111325866dfc688c6618c

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.001 antivm_network_adapters: Checks NIC addresses
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antivm_network_adapters: Checks NIC addresses
T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Other

yara_rules: Static rules
suricata_alert: Malicious traffic detected
only_exec_in_archive: The archive contains only an executable file
no_graphical_activity: No graphic activity
dotnet_import_unmanaged_code: Dotnet statically imports unmanaged functions/modules
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
dotnet_downloader_possible_network_problem: Dotnet downloader possibly has network problem