Managed XDR

vtdl_1738710407_ayb2d2ol — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl_1738710407_ayb2d2ol
Тип файла
PE32 executable (console) Intel 80386, for MS Windows, UPX compressed
Размер файла
252 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
be4a0c24ccab6dd0e8d2d22ea4480492c5ff252e
SHA256
14580417a18f7a6a51dffdbaa81d5f65dd4242d42008dfc4063a216520b7f9fd
MD5
82b8221d49674b02b8feee507fc9634a

Сигнатуры

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_upx: The executable file is compressed using UPX
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1552.002 opens_registry_hive_file: Attempts to open Windows registry hive file
T1003.002 opens_registry_hive_file: Attempts to open Windows registry hive file

Other

yara_rules: Static rules