Managed XDR

vtdl_1752088905_yknpwjxa (Nitol, Gh0st, Hupigon) — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl_1752088905_yknpwjxa
Тип файла
PE32 executable (GUI) Intel 80386, for MS Windows
Размер файла
716.5 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
73a019166ec827e2e9b8c9cf07c52f0e9f7cbac1
SHA256
3a1af301e0a2b3ac84455bb92b0f191567a2b252a31cbbd3cf4c127b0ac05422
MD5
a0f5a7523474afc1248ff8bcf9c1fe3f

Вредоносное ПО

  • Nitol
  • Gh0st
  • Hupigon

Сигнатуры

Execution

T1569.002 persistence_service: Starts newly created service

Persistence

T1543.003 creates_service: Creates a service, that will start automatically
T1574 dropper_dll: Creates DLL, which is then loaded into the process

Privilege Escalation

T1543.003 creates_service: Creates a service, that will start automatically
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1564.001 stealth_file: Creates hidden or system files
T1027.002 unnamed_memory_regions_contains_pe: One or several unnamed memory regions are PE files
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
creates_exe: Creates executable files in the file system
executes_dropped_exe: Executes dropped exe files
creates_in_windows: Creates files in the Windows directory
dns_without_resolve: DNS query without a response
dns_tld_cc: Connects to TLD .CC, possibly malware
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
break_limit_exceeded: Warning: function calls limit has been exceeded
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
suricata_alert: Malicious traffic detected

Похожие отчёты

Managed XDR