Managed XDR

vtdl_1751937943_8hxp8z2x — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl_1751937943_8hxp8z2x
Тип файла
PE32 executable (GUI) Intel 80386, for MS Windows
Размер файла
498.5 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x64 en

Хеши

SHA1
3e736f6858a8f99e968d4459cfdce8bfc8a29d2b
SHA256
572fb8c5c3eb8eda7e457701b69f0219c6b7a9f9a148c12517c197a2411d0945
MD5
a2e94e6bc75c0d1da4230856bf33e47d

Сигнатуры

Persistence

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup

Privilege Escalation

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1562.001 disables_security: Disables Windows Security options
T1112 stealth_hide_notifications: Attempts to change notification settings
T1562 modify_security_center_warnings: Attempts to modify or disable Security Center notifications
T1562 disables_uac: Disable UAC
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Impact

T1489 stops_service: Stops Windows services

Other

copies_self: Creates a copy of itself
creates_exe: Creates executable files in the file system
dead_host: Connects to IP addresses that do not respond to requests
bazar_loader: Exhibits behavior characteristics of BazarLoader
no_graphical_activity: No graphic activity
creates_in_programdata: Creates files in the ProgramData directory