Managed XDR

vtdl_vwd24jmy (Thanos, AsyncRAT) — malware analysis report

File info

Filename
vtdl_vwd24jmy
File type
RAR archive data, v5
File size
278.1 KB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
3d037f59de597de482b558cacdb4fa700197ab20
SHA256
411e7807a527fd69fbd3bbc229d71947a21be7b1d8cc6f4793df88b54607887e
MD5
2c604437fa06dac31e596e4fccf2042c

Malwares

  • Thanos
  • AsyncRAT

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.001 antivm_disk_size: Checks the amount of free disk space
T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antivm_disk_size: Checks the amount of free disk space
T1497.001 antivm_queries_computername: Retrieves the computer name

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
has_pdb: This executable file has a PDB path
dotnet_suspicious_module_name: Dotnet program has suspicious module name
dotnet_import_unmanaged_code: Dotnet program statically imports unmanaged functions/modules
break_limit_exceeded: Warning: function calls limit has been exceeded
dotnet_obfuscated: Dotnet program is potentially obfuscated
checktokenmembership: Checks user token with CheckTokenMembership call
pe_overlay: PE file contains overlay
dotnet_suspicious_entrypoint: Dotnet program has suspicious entrypoint
dotnet_downloader_possible_network_problem: Dotnet program possibly has network problem

Related reports