Managed XDR

atmlib.dll — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
atmlib.dll
Тип файла
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
Размер файла
24 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x64 en

Хеши

SHA1
85060b8e7595d2518b8efc6d8c5dba16647cdcb6
SHA256
deeee09ba51858e4f66d4adbb5f50e5992ece5243222b1e88622145d25495f58
MD5
7559385102d5a7fed10ee7fd79300f28

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
message_box: Displays a message