Managed XDR

dvdstyler.exe (Hupigon) — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
dvdstyler.exe
Тип файла
PE32 executable (GUI) Intel 80386, for MS Windows
Размер файла
3.6 MB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
a67f6ae689dbfdfe8901095645ebe8e6d99082e8
SHA256
a7cd49301d28a7724cd2b248d930398c80cfe2b2aac156cbf92608821ea1d6b1
MD5
5b7238e3543a0f49725f3ac5c1921867

Вредоносное ПО

  • Hupigon

Сигнатуры

Privilege Escalation

T1134 sets_privilegies_via_rtladjustprivilege: Sets process privilege via RtlAdjustPrivilege
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1036.001 invalid_authenticode: Digital signature of the executable file has failed the verification
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1134 sets_privilegies_via_rtladjustprivilege: Sets process privilege via RtlAdjustPrivilege
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1552 infostealer_browser: Retrieves personal information from local Internet browsers
T1503 infostealer_browser: Retrieves personal information from local Internet browsers

Discovery

T1518.001 antiav_detectfile: Attempts to detect installed antiviruses by a certain directory
T1057 process_interest: Enumerates processes

Command and Control

T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp

Other

yara_rules: Static rules
dns_without_resolve: DNS query without a response
message_box: Displays a message
origin_langid: Unconventional language of the executable file
pe_overlay: PE file contains overlay
open_event_log: Opens an event log

Похожие отчёты