Managed XDR

vtdl_8c109u_d — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl_8c109u_d
Тип файла
RFC 822 mail, ASCII text, with CRLF line terminators
Размер файла
2.6 MB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x64 en

Хеши

SHA1
347bee43e23308aa04323bf75d2176fa0f3d7bbb
SHA256
3a4a3491d2d00c66153c633d6367d75243538ba57e310ac9545351117ee05a07
MD5
03ed4f63215f565eb003317311ec88e0

Сигнатуры

Execution

T1059.001 suspicious_powershell: Creates suspicious powershell process

Privilege Escalation

T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1036 copies_utilities: Copies and runs system utility with different name
T1564.001 stealth_file: Creates hidden or system files
T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antivm_queries_computername: Retrieves the computer name

Other

executes_dropped_exe: Executes dropped exe files