Managed XDR

vtdl_1789685029_4jypzby5 — malware analysis report

File info

Filename
vtdl_1789685029_4jypzby5
File type
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has command line arguments, Icon number=0, Archive, ctime=Wed Oct 6 13:31:20 2021, mtime=Tue Jun 28 12:21:18 2022, atime=Wed Oct 6 13:31:20 2021, length=236544, window=hidenormalshowminimized
File size
2.7 KB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
83debfe71cfcdf76f98547cc375de48a9440a988
SHA256
d27666924182a5311118cfd39e073222d69e365bdd00e0efc1f407ba94009c62
MD5
f254cd989a4eeac2a8d89e5e86e05607

Signatures

Execution

T1204 suspicious_lnk: LNK file with suspicious content
T1047 antivm_wmi: Uses WMI to detect virtual environment
T1047 has_wmi: Executes one or several WMI requests
T1059.001 url_cmdline: Cmdline of process contains URL
T1059.003 url_cmdline: Cmdline of process contains URL

Defense Evasion

T1218 suspicious_cmdline: Executes a suspicious command
T1497.001 antivm_wmi: Uses WMI to detect virtual environment
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization

Discovery

T1497.001 antivm_wmi: Uses WMI to detect virtual environment
T1082 has_wmi: Executes one or several WMI requests
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization

Command and Control

T1105 cmdline_curl: Uses curl utility for network data transferring

Other

dead_host: Connects to IP addresses that do not respond to requests
creates_suspended_process: Creates suspended process
suspicious_network_port: Performs TCP or UDP request to non-standard port
test_check_service: Starts services
yara_rules: Static rules