Managed XDR

vicidial_webrtc_driver_1.0.exe — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vicidial_webrtc_driver_1.0.exe
Тип файла
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
Размер файла
28.3 MB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
7a00a24a324593a86e4e87c7fbc31dab40722b68
SHA256
fa3ea8354a6546dfd20ab463ee16f6b98fbc3833de9f94bbe98f5c96dfebe902
MD5
a1eadfca4fa3ba1dcd7a67aa06e413bf

Сигнатуры

Persistence

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup

Privilege Escalation

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1518 locates_browser: Attempts to identify where browsers are installed

Other

create_process_failed: Could not start the process
no_graphical_activity: No graphic activity
creates_exe: Creates executable files in the file system