Managed XDR

vtdl_i9shb6l8 — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl_i9shb6l8
Тип файла
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=1, Archive, ctime=Wed Nov 15 19:52:45 2023, mtime=Sat Jan 27 04:07:55 2024, atime=Wed Nov 15 19:52:45 2023, length=867328, window=hidenormalshowminimized
Размер файла
3 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
8f94ab67ef2ffc221eb12f8ad74f2e0b62ea2d15
SHA256
820d824d3b622ae3b349c9367b6ba272c3ab2461416ed32fc869ba55bb369e65
MD5
ddee318c9f2bbf4938ec1ea5cd4227b0

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object