Managed XDR

1499199945.m83867p5173...br-s-25430-w-25802-2-s — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
1499199945.m83867p517331.br540.hostgator.com.br-s-25430-w-25802-2-s
Тип файла
SMTP mail, ASCII text
Размер файла
24.8 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
fe2da581572925e144cf70596b94df38df018386
SHA256
8d95cc75a31811cf5e7fdb74cf948e2c5caeaa451a31003d940593f26b86547d
MD5
79e32b471de026fc84ef35b1b4ec3c2b

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
dead_host: Connects to IP addresses that do not respond to requests
creates_in_programdata: Creates files in the ProgramData directory