Managed XDR

vtdl_21ief7lj — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl_21ief7lj
Тип файла
RFC 822 mail, ASCII text, with CRLF line terminators
Размер файла
113 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
14d71ccadcc239ca0fe23bc309741ee783544efc
SHA256
7c244b18824ecb0849a3179c776e53726912cc959b8ceb171f1c5bba171f1fc6
MD5
bb4e1ae4acf11412f4f132339d7a82bd

Сигнатуры

Defense Evasion

T1497.002 async_mouse: Watches for mouse clicks using GetAsyncKeyState to detect human activity

Discovery

T1497.002 async_mouse: Watches for mouse clicks using GetAsyncKeyState to detect human activity

Other

yara_rules: Static rules
suspicious_pdf: PDF file with suspicious content
pdf_page: Contains only one page
create_rpc_bindings: Creates RPC connection
pdf_compressed_stream: Contains an object with compressed stream
get_sid_domain: Get user's SID
office_links: Office file contains external links
get_memory_status: Gets information about the virtual and physical memory of the system