Managed XDR

vtdl_1737552961_ewuhulsd (Vidar, Stealc) — malware analysis report

File info

Filename
vtdl_1737552961_ewuhulsd
File type
PE32 executable (GUI) Intel 80386, for MS Windows
File size
296.5 KB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
0c47110afa4fb1619463906448769ea40453bb38
SHA256
76e6f014771dee8f671da1d2bfaacb1a26940da6d83b005bd81b86d9472611ac
MD5
9b11a33928c2fbbe5b4d2fe5cc29d2ac

Malwares

  • Vidar
  • Stealc

Signatures

Resource Development

T1585.001 social_telegram: Connects to Telegram (potentially for information gathering)
T1586.001 social_telegram: Connects to Telegram (potentially for information gathering)

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Command and Control

T1071 internet_security_options: Sets Internet connections options that are not secure
T1032 internet_security_options: Sets Internet connections options that are not secure
T1071.001 wininet_https: Performs HTTP/HTTPS requests using WinInet

Other

suricata_alert: Malicious traffic detected
no_graphical_activity: No graphic activity
origin_langid: Unconventional language of the executable file

Related reports