Managed XDR

vtdl_je4gfe2d — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl_je4gfe2d
Тип файла
RAR archive data, v5
Размер файла
840.7 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
a7e3b0469aa9ea5fcc529b32cb2a4e6883ed3df7
SHA256
a0cec7362adb7b533559aa8103369123ea5ad156f0df940cc5dc65dba521bdfb
MD5
7d441089a119819e6ddf13836adf7924

Сигнатуры

Persistence

T1574 dropper_dll: Creates DLL, which is then loaded into the process

Privilege Escalation

T1574 dropper_dll: Creates DLL, which is then loaded into the process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1574 dropper_dll: Creates DLL, which is then loaded into the process

Discovery

T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Other

yara_rules: Static rules
creates_exe: Creates executable files in the file system
only_exec_in_archive: The archive contains only an executable file
create_rpc_bindings: Creates RPC connection
require_administrator: Requests administrator privileges
get_memory_status: Gets information about the virtual and physical memory of the system