Managed XDR

vtdl_poyk_mnw — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl_poyk_mnw
Тип файла
RFC 822 mail, ASCII text, with CRLF line terminators
Размер файла
118.8 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
027cdda568918670d7106d88157ce015bbd5ae49
SHA256
09158a8d8cc8796ad40951390963dcf3b0e2a84a3d7e4b7492f695a2f5ffc35d
MD5
e4d6e614eb66cd6a577e3525b9cb0273

Сигнатуры

Command and Control

T1102.003 references_azure: Contains links to cloud services of Azure (potentially for malicious payload delivery)

Other

yara_rules: Static rules
suspicious_pdf: PDF file with suspicious content
pdf_page: Contains only one page
create_rpc_bindings: Creates RPC connection
pdf_compressed_stream: Contains an object with compressed stream
get_sid_domain: Get user's SID
office_links: Office file contains external links
get_memory_status: Gets information about the virtual and physical memory of the system