Managed XDR

wrf-418ddc38-51d3-4a93...87d1-e13fe8239688-.tmp — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
wrf-418ddc38-51d3-4a93-87d1-e13fe8239688-.tmp
Тип файла
Composite Document File V2 Document, Cannot read section info
Размер файла
98.8 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
7838cf358429ba3012325ee066c1c1e3e4733e2c
SHA256
3df9bdd01717aa7f3b0c4634659793fbdb9151497bc641b36eb466df6adb447f
MD5
f518414fc64c925faf35bf4983931426

Сигнатуры

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1056.001 infostealer_keylogger: Keylogger (intercepts keystrokes)

Collection

T1056.001 infostealer_keylogger: Keylogger (intercepts keystrokes)

Other

yara_rules: Static rules
creates_in_windows: Creates files in the Windows directory
creates_exe: Creates executable files in the file system
process_crashed: One of the processes has failed
no_graphical_activity: No graphic activity