Managed XDR

a74adc926d950d4316558f...1761445897668986668.gz — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
a74adc926d950d4316558fa6b6162724fcdd6a40f0b87566cd2963f867d203d4-1761445897668986668.gz
Тип файла
gzip compressed data
Размер файла
2.3 MB
Первое обнаружение
Последнее обнаружение

Окружение

w10/x64 en

Хеши

SHA1
d6866f7b258a331e276e479e52be133cbaa01309
SHA256
c03b29fc9b8af50e5f87abd86f52b03253c66b2264bc6dfabf8476da81f9d9e0
MD5
86579335bc30888f2c46087b6c93c4cd

Сигнатуры

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_polymorphic: Creates a modified copy of itself
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1518 locates_browser: Attempts to identify where browsers are installed

Collection

T1074.001 access_recyclebin: Manipulation with recyclebin detected

Other

creates_exe: Creates executable files in the file system
creates_doc: Creates (office) documents in the file system
only_exec_in_archive: The archive contains only an executable file
writes_data: Writes big amount of data to disk
pe_overlay: PE file contains overlay