Managed XDR

vtdl_t0venb5r — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl_t0venb5r
Тип файла
MS Windows shortcut, Item id list present, ctime=Mon Dec 31 17:50:36 2012, mtime=Mon Dec 31 17:50:36 2012, atime=Mon Dec 31 17:50:36 2012, length=0, window=hide
Размер файла
3.5 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
6c8a45c67158aff3ab3227eccc045ca5ccdcafae
SHA256
61602bb611d7de09e2f85e971af0a3d55615879627a5f8744ba5b4869df9d818
MD5
cefc375a88838fe8bd262835dd7afa87

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process