Managed XDR

5a8b05e838b2091a0d560a...1751599822153359195.gz — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
5a8b05e838b2091a0d560a6ada2e10faec9229159feaa90844e6960fd647b54e-1751599822153359195.gz
Тип файла
gzip compressed data
Размер файла
2.5 MB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x64 en

Хеши

SHA1
be3b40378c6f4de9edc6a7956073cd435146f915
SHA256
30f0ad3d1f8841ab4eda9f44cf6117c22d1da2ae93765e3d2dc1eb9d25c45866
MD5
d515a6a853fc32653ff153aed1187d1d

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1518 locates_browser: Attempts to identify where browsers are installed

Collection

T1074.001 access_recyclebin: Manipulation with recyclebin detected

Other

yara_rules: Static rules
creates_exe: Creates executable files in the file system
creates_der: Creates a certificate file (DER)
creates_doc: Creates (office) documents in the file system
only_exec_in_archive: The archive contains only an executable file
writes_data: Writes big amount of data to disk
pe_overlay: PE file contains overlay