Managed XDR

vtdl_sa6ax73e — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl_sa6ax73e
Тип файла
Rich Text Format data, version 1, ANSI
Размер файла
239.2 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
2ed31536742e5f536c105d1620eed1abce5b1b94
SHA256
461d9c2ca130c482c725a18f73f22f88a37c021757a4cc7d251d2ffcaa617932
MD5
c3c0fb66dbf629b58818cd111a917f65

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1083 checks_recent_files: Attempt to check recently opened files through registry

Other

yara_rules: Static rules
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card