Managed XDR

pet-pictures-some-requ...t-phone-number.rar.bat — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
pet-pictures-some-requirements-address-contact-phone-number.rar.bat
Тип файла
Little-endian UTF-16 Unicode text, with very long lines, with no line terminators
Размер файла
512.1 KB
Первое обнаружение
Последнее обнаружение

Окружение

w10/x64 en

Хеши

SHA1
d8e2f917aac72cad2b6ef0e5f4f671b498e42a6a
SHA256
2b7769a09de8f61aef1ee746e515b1d51cd834e4d3cd66124f274db468439b20
MD5
c997d94a77dde5065b32a759e9d85900

Сигнатуры

Resource Development

T1608.005 contacts_url_shortener: Connects to url shortening services

Execution

T1059.001 suspicious_powershell: Creates suspicious powershell process
T1204.002 mimics_extension: Attempts to mimic the file extension
T1059.001 suspicious_process: Spawns a suspicious process
T1059.001 url_cmdline: Cmdline of process contains URL
T1059.003 suspicious_batch: Suspicious batch
T1059.003 url_cmdline: Cmdline of process contains URL

Defense Evasion

T1036 mimics_extension: Attempts to mimic the file extension
T1497.003 antisandbox_idletime: Detects Windows Idle Time to determine the uptime

Discovery

T1497.003 antisandbox_idletime: Detects Windows Idle Time to determine the uptime
T1518 locates_browser: Attempts to identify where browsers are installed

Other

network_powershell: Powershell process network connection detected
no_graphical_activity: No graphic activity
creates_suspended_process: Creates suspended process
suricata_alert: Malicious traffic detected