Managed XDR

vtdl_4_hsdskr — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl_4_hsdskr
Тип файла
MS Windows shortcut, Item id list present, ctime=Thu Apr 19 11:26:04 2012, mtime=Thu Apr 19 11:26:04 2012, atime=Thu Apr 19 11:26:04 2012, length=0, window=hide
Размер файла
1.1 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
79ba26973b96e4ff87fe73952f4a014b1c64a0c1
SHA256
931d670ad7f0360ee43df6b3de69a4a785f287165b8dec38b8e93a427905f52c
MD5
cebb464819e7fa6988428edb48cd6c47

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process