Managed XDR

vtdl_iqpetxul — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl_iqpetxul
Тип файла
PE32 executable (GUI) Intel 80386, for MS Windows
Размер файла
4.1 MB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
2eba071e92efa41273b3e0dbdf9436e7086cc651
SHA256
04623031cca8559b51c42ef3170d89a94b6d8dea9af0b1790eaf53e6cab0671f
MD5
707cc8a10d84d604371e8e1f2f8346b3

Сигнатуры

Defense Evasion

T1036.001 invalid_authenticode: Digital signature of the executable file has failed the verification
T1027.002 packer_entropy: Probably contains compressed or encrypted data

Command and Control

T1102.003 cloud_discord: Connects to cloud services of Discord (potentially for malicious payload delivery)

Other

ip_domains: Identifies an IP address using external resources
dns_without_resolve: DNS query without a response
SipStun: Connects to the SIP Stun server
no_graphical_activity: No graphic activity
suspicious_network_port: Performs TCP or UDP request to non-standard port
pe_overlay: PE file contains overlay
suricata_alert: Malicious traffic detected