Managed XDR

vtdl_1783068825__1_3kbuu — malware analysis report

File info

Filename
vtdl_1783068825__1_3kbuu
File type
SMTP mail, UTF-8 Unicode text, with very long lines, with CRLF line terminators
File size
30.8 KB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
b43e7b889ed6d86ce0dd2c22f1472d967cc6d7cd
SHA256
92e69410d63b9f5dcec8a0b6f720e19213d3e79e84e10a8a6f4fe083d3a49934
MD5
86bf5d517b151ea1471fd54e3c189f0c

Signatures

Execution

T1047 antivm_wmi: Uses WMI to detect virtual environment
T1047 has_wmi: Executes one or several WMI requests

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.001 antivm_wmi: Uses WMI to detect virtual environment
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization
T1070 stealth_window: A process created a hidden window
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1555.004 windows_credential_manager: Acquire credentials from the Windows Credential Manager

Discovery

T1497.001 antivm_wmi: Uses WMI to detect virtual environment
T1057 has_wmi: Executes one or several WMI requests
T1082 has_wmi: Executes one or several WMI requests
T1518 locates_browser: Attempts to identify where browsers are installed
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization

Command and Control

T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp
T1071.001 wininet_https: Performs HTTP/HTTPS requests using WinInet

Other

suricata_alert: Malicious traffic detected
network_bind: Starts servers listening at None
suspicious_process_network: Unusual process network activity detected
creates_doc: Creates (office) documents in the file system
no_graphical_activity: No graphic activity
create_rpc_bindings: Creates RPC connection
creates_suspended_process: Creates suspended process
changes_ext_type: File extension changed from executable to non-executable or vice versa
suspicious_network_port: Performs TCP or UDP request to non-standard port
test_check_service: Starts services
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card