Managed XDR

untitled-2.bat — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
untitled-2.bat
Тип файла
Rich Text Format data, version 1, ANSI
Размер файла
1.2 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
e27066d437b6155279f391917cf09cfd37832307
SHA256
8c0cae73f0ac67589f0e2137264faa40872b976cd99f85263e47af4f05ad6e18
MD5
2950bcf638ce28b205825e675696c88d

Сигнатуры

Execution

T1053.005 persistence_autorun: Makes itself run automatically on Windows startup

Persistence

T1053.005 persistence_autorun: Makes itself run automatically on Windows startup

Privilege Escalation

T1053.005 persistence_autorun: Makes itself run automatically on Windows startup
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1518 locates_browser: Attempts to identify where browsers are installed

Other

yara_rules: Static rules
creates_exe: Creates executable files in the file system
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
office_links: Office file contains external links
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card
checktokenmembership: Checks user token with CheckTokenMembership call