Managed XDR

banned-20250319t122745-18629-13 — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
banned-20250319t122745-18629-13
Тип файла
SMTP mail, UTF-8 Unicode text
Размер файла
853.5 KB
Первое обнаружение
Последнее обнаружение

Окружение

w10/x86 en

Хеши

SHA1
f5f2078dd37b6f2a6525946656dc02c73d95cbbe
SHA256
5a9669384c72c68c8f0324a2b9db21d6bd7d086e7a71d0932548328847a16f75
MD5
6d14e68acec8337a86409bf402e10a45

Сигнатуры

Initial Access

T1192 html_urls: HTML-document downloads a file

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
dotnet_suspicious_resources_names: Dotnet program has suspicious resources names
dotnet_obfuscated: Dotnet program is potentially obfuscated
test_check_service: Starts services
dotnet_suspicious_entrypoint: Dotnet program has suspicious entrypoint
suricata_alert: Malicious traffic detected
dotnet_downloader_possible_network_problem: Dotnet program possibly has network problem