Managed XDR

689df913e8a92a6005d6ae...4dc8f65c58-dropped.bin — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
689df913e8a92a6005d6ae70c9e0da7dabb7cb3bfa65a415c618e94dc8f65c58-dropped.bin
Тип файла
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Размер файла
13 MB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
45d39e139b07664b9d1c5bc0f6f9456c52dd1fbe
SHA256
689df913e8a92a6005d6ae70c9e0da7dabb7cb3bfa65a415c618e94dc8f65c58
MD5
e5e6dc5b7121c6011b0e0341ffc25dee

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
message_box: Displays a message
pe_overlay: PE file contains overlay