Managed XDR

re_-rfq-for-spare-parts.msg (DarkGate) — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
re_-rfq-for-spare-parts.msg
Тип файла
CDFV2 Microsoft Outlook Message
Размер файла
580.5 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
6b32de0b5acaf8bc3c9357d35f7ec5e62f121f3a
SHA256
d8172c0294f9f6ffad83e479a53f8f5f30914bf957245784979e4fc1da51f096
MD5
35a830167a3c0b0b9a78a4969979941f

Вредоносное ПО

  • DarkGate

Сигнатуры

Execution

T1059 autoit: AutoIt script execution detected
T1059 autoit_suspicious_script: Autoit contains suspicious script

Persistence

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup

Privilege Escalation

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1055 injection_failed: The attempt to inject into a process has failed

Defense Evasion

T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1070 stealth_window: A process created a hidden window
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1055 injection_failed: The attempt to inject into a process has failed

Other

yara_rules: Static rules
copies_self: Creates a copy of itself
creates_exe: Creates executable files in the file system
suspicious_process: Spawns a suspicious process
executes_dropped_exe: Executes dropped exe files
process_crashed: One of the processes has failed
no_graphical_activity: No graphic activity
creates_suspended_process: Creates suspended process
test_check_service: Starts services

Похожие отчёты