Managed XDR

2026-07-29_df941eb4038...oke-loader_stealc_stop — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
2026-07-29_df941eb4038de8e8e959f7f03a0a4ee8_amadey_darkgate_elex_luca-stealer_njrat_remcos_rhadamanthys_smoke-loader_stealc_stop
Тип файла
PE32 executable (GUI) Intel 80386, for MS Windows
Размер файла
7.3 MB
Первое обнаружение
Последнее обнаружение

Окружение

w10/x64 en

Хеши

SHA1
59b2a8123afcf00917e9c8b9d558e1c625b9f6da
SHA256
d22c7274103cc2042eb76a06097d7efdaceeb2694f5b82f91874aa20ad61225f
MD5
df941eb4038de8e8e959f7f03a0a4ee8

Сигнатуры

Persistence

T1547.004 persistence_autorun: Makes itself run automatically on Windows startup

Privilege Escalation

T1547.004 persistence_autorun: Makes itself run automatically on Windows startup
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1555.004 windows_credential_manager: Acquire credentials from the Windows Credential Manager

Discovery

T1057 process_interest: Enumerates processes
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization

Command and Control

T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp

Impact

T1485 deletes_files: Removes 100 or more files from C: drive

Other

creates_exe: Creates executable files in the file system
creates_in_windows: Creates files in the Windows directory
copies_self: Creates a copy of itself
static_pe_anomaly: The PE file structure contains anomalies
network_bind: Starts servers listening at None
no_graphical_activity: No graphic activity
has_pdb: This executable file has a PDB path
suspicious_network_port: Performs TCP or UDP request to non-standard port
test_check_service: Starts services
writes_data: Writes big amount of data to disk
pe_overlay: PE file contains overlay
yara_rules: Static rules