Managed XDR

5c6877c061a163a29bd7bdc1243850ef.virus — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
5c6877c061a163a29bd7bdc1243850ef.virus
Тип файла
MS Windows shortcut, Item id list present, Has command line arguments, Icon number=3, ctime=Mon Jan 1 00:00:00 1601, mtime=Mon Jan 1 00:00:00 1601, atime=Mon Jan 1 00:00:00 1601, length=0, window=hidenormalshowminimized
Размер файла
788 Bytes
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
d3d19ec8f57824c71097c503ef263ebbfebc56a4
SHA256
e015e3eefdf65a75dceac2bb4fa5b3a690c5764c724cac05d4e54c1c5ad0a2b9
MD5
5c6877c061a163a29bd7bdc1243850ef

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object