Managed XDR

template.pdf — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
template.pdf
Тип файла
Composite Document File V2 Document, Little Endian, Os: Windows, Version 1.0
Размер файла
10 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
3a0593fd8c93d840b57eb293be49bb1b5bd8b023
SHA256
751fdbe07fd5b46d78bbf41ab4d130b0ab8f02d6dd45d6e52c5f69ad8922fa2a
MD5
f79eb66344d598ece7c772eae5ef8ec2

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
get_policy_info: Retrieves information about a Policy object