Managed XDR

13c5600ff17c2990add0581c8466a664.virus — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
13c5600ff17c2990add0581c8466a664.virus
Тип файла
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
Размер файла
416 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
1e26cc1a1ed6429ecfeed8055999fd3fa3c080d9
SHA256
5f1e96455f4f39a31f91166beee4368f8c74329e95b9d2a1733ad9420bbb05b2
MD5
13c5600ff17c2990add0581c8466a664

Сигнатуры

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_process_token: Opens the access token associated with a process
T1027.002 packer_aspack: Executable file is packed with ASPack
T1027.002 packer_entropy: Probably contains compressed or encrypted data

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
protector_asprotect: Executable file is protected with ASProtect