Managed XDR

vtdl_1789024493_kpi9sd0_ (Remcos) — malware analysis report

File info

Filename
vtdl_1789024493_kpi9sd0_
File type
Composite Document File V2 Document, No summary info
File size
121.5 KB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
af5de43218f128a3aa18031f123d4791e361eac3
SHA256
559c556615dc2d9a938c71fc7161bc864f7f9a8aa022253c63e2791c2ef29904
MD5
02c1e35c3af928a00557892885f04a9a

Malwares

  • Remcos

Signatures

Execution

T1053.005 creates_tasks: Creates a delayed task using Task Scheduler
T1053.005 persistence_autorun: Makes itself run automatically on Windows startup

Persistence

T1053.005 creates_tasks: Creates a delayed task using Task Scheduler
T1053.005 persistence_autorun: Makes itself run automatically on Windows startup

Privilege Escalation

T1055.002 inject_write_pe: Writes PE file to another process's memory
T1055.012 injection_runpe: Injects code into another process
T1053.005 creates_tasks: Creates a delayed task using Task Scheduler
T1053.005 persistence_autorun: Makes itself run automatically on Windows startup
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1055.002 inject_write_pe: Writes PE file to another process's memory
T1055.012 injection_runpe: Injects code into another process
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1027.004 compiles_code: Compiles C# code
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1027.001 static_overlay_padding: Overlay contents padding
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1555.004 windows_credential_manager: Acquire credentials from the Windows Credential Manager

Discovery

T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers

Command and Control

T1102.003 references_google: Contains links to cloud services of Google (potentially for malicious payload delivery)
T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp

Other

yara_rules: Static rules
ce_info: Remcos Configuration Data found
unpacker_wrong_base: Possibly, an error occurred in the file unpacker
copies_self: Creates a copy of itself
network_bind: Starts servers listening at None
creates_exe: Creates executable files in the file system
dotnet_obfuscated: Dotnet program is potentially obfuscated
process_crashed: One of the processes has failed
dotnet_suspicious_resources_names: Dotnet program has suspicious resources names
dotnet_suspicious_module_name: Dotnet program has suspicious module name
creates_suspended_process: Creates suspended process
static_compression_ratio: Very high compression ratio of a file
suspicious_network_port: Performs TCP or UDP request to non-standard port
test_check_service: Starts services
checktokenmembership: Checks user token with CheckTokenMembership call
writes_data: Writes big amount of data to disk
pe_overlay: PE file contains overlay
static_big_overlay: Executable file contains an enormously big overlay

Related reports