Managed XDR

vtdl_wono5grd — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl_wono5grd
Тип файла
MS Windows shortcut, Item id list present, ctime=Tue Sep 24 09:19:26 2024, mtime=Tue Sep 24 09:19:26 2024, atime=Tue Sep 24 09:19:26 2024, length=0, window=hide
Размер файла
1.1 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
ed0c3d6585bbd158a9fdff80921f1f23bd9e01ec
SHA256
aff7f10c6a60e058ad0a57d4bbab5ff5b64813ba807ccdd852758464f450010c
MD5
e082085cec3a487cf0dda8ff660254d2

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process