Managed XDR

northlandvideoconvert — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
northlandvideoconvert
Тип файла
PE32 executable (GUI) Intel 80386, for MS Windows
Размер файла
14.2 MB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
49528e621ced7994c1b7ba02313ce3f20cac82f7
SHA256
097532b9a35fe88c628b04f7bb36923fef3500cecf90357261a8d4d6613d5c75
MD5
98d8c9058ceb5066befaa334d96278fe

Сигнатуры

Execution

T1059.001 suspicious_powershell: Creates suspicious powershell process
T1059.001 suspicious_process: Spawns a suspicious process
T1059.003 suspicious_batch: Suspicious batch

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.001 antivm_disk_size: Checks the amount of free disk space
T1497.003 antisandbox_sleep_utilities: Uses Windows utilities for pausing the execution
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antivm_disk_size: Checks the amount of free disk space
T1497.003 antisandbox_sleep_utilities: Uses Windows utilities for pausing the execution
T1016.001 system_network_configuration_discovery: System network configuration discovery detected
T1082 recon_systeminfo: Collects system information (ipconfig, netstat, systeminfo, net)

Other

creates_exe: Creates executable files in the file system
network_anomaly: Network anomalies occured during the analysis
no_graphical_activity: No graphic activity
has_pdb: This executable file has a PDB path
message_box: Displays a message
creates_in_programdata: Creates files in the ProgramData directory