Managed XDR

backdoor_gamarue_2021_347.exe — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
backdoor_gamarue_2021_347.exe
Тип файла
PE32 executable (GUI) Intel 80386, for MS Windows
Размер файла
290 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
a2cacaba2760e2b28bcd1d385ea712b3b9434f44
SHA256
ff01a90a8d1c2a4bde2eaec1c91388663a034a19b7f8bd01b3f10c70bbd670bb
MD5
31ef6162f7c5bd612afbe5d6d0d46ed1

Сигнатуры

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
no_graphical_activity: No graphic activity
has_pdb: This executable file has a PDB path