Managed XDR

remittance-board-inv-6...nce-board-inv-6214.exe — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
remittance-board-inv-6214-remittance-board-inv-6214.exe
Тип файла
PE32 executable (GUI) Intel 80386, for MS Windows
Размер файла
1.3 MB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
3242f15892ec2893348f02ec8e84ad2ea56ecf47
SHA256
e7418fa07dae4a7bd642b9a3d95b839ad7493030e5fed6fc685f116e36c20a44
MD5
9fadd62d2fe11693d9eee855b84dc3ef

Сигнатуры

Execution

T1059.005 obfuscated_vbs: Detected obfuscated VBS

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1027 obfuscated_vbs: Detected obfuscated VBS
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1135 server_share_info: Retrieves information about each shared resource on a server

Other

yara_rules: Static rules
creates_exe: Creates executable files in the file system
creates_doc: Creates (office) documents in the file system
http_file_not_found: Attempts to download EXE or DLL file but receives HTML with an error
create_rpc_bindings: Creates RPC connection
has_pdb: This executable file has a PDB path
test_check_service: Starts services
checktokenmembership: Checks user token with CheckTokenMembership call
pe_overlay: PE file contains overlay