Managed XDR

scratch-zoo-2025-03-07...0612e2aba726c871a7f03d — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
scratch-zoo-2025-03-07-5e99b051320612e2aba726c871a7f03d
Тип файла
SMTP mail, ASCII text, with very long lines
Размер файла
3.2 MB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
5f374769dfb9d1bb300e8c349f6d3f5fb13951ec
SHA256
36cf442112187e04ec4834d983be0c0d8237cf7db6f57cc4020413ba64af9088
MD5
5e99b051320612e2aba726c871a7f03d

Сигнатуры

Privilege Escalation

T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
get_policy_info: Retrieves information about a Policy object
dotnet_suspicious_entrypoint: Dotnet program has suspicious entrypoint
dotnet_suspicious_module_name: Dotnet program has suspicious module name