Managed XDR

vtdl_hc774ilt — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl_hc774ilt
Тип файла
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
Размер файла
5.4 MB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
550a6e7e74ca6a01c10e45906e7eb5314f414d3f
SHA256
b203bbe228b2e64f06fad0ff4db8ae2ab37093c0fde6189e03eee853461b98e9
MD5
f5502415851762542df657669c0cb764

Сигнатуры

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process
T1055 injection_failed: The attempt to inject into a process has failed

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_process_token: Opens the access token associated with a process
T1055 injection_failed: The attempt to inject into a process has failed

Discovery

T1057 process_interest: Enumerates processes

Other

yara_rules: Static rules
copies_self: Creates a copy of itself
creates_exe: Creates executable files in the file system
executes_dropped_exe: Executes dropped exe files
process_crashed: One of the processes has failed
no_graphical_activity: No graphic activity
access_recyclebin: Manipulation with recyclebin detected
test_check_service: Starts services
writes_data: Writes big amount of data to disk