Managed XDR
Group-IB MDP Report
Filename: vtdl_gpzu733h
File Type: RAR archive data, v4, os: Win32
File Size: 223.9 KB
SHA1: 207504c8aed5e8efa63402c5fea2ad3f1596c99e SHA256: f22b71ebc7d0a21caf70dc0f28a36f0a5834f6536a950af1d3886770d3dd3a9b MD5: c7ff0a792153bf864745f307c839db62
Signatures
Privilege Escalation
T1055.012 injection_runpe: Injects code into another process
T1055 injection_runpe_2: Executes injected code in another process
T1055 sets_debug_registers: Sets debug registers for a thread in a different process
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
Defense Evasion
T1055.012 injection_runpe: Injects code into another process
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1055 injection_runpe_2: Executes injected code in another process
T1055 sets_debug_registers: Sets debug registers for a thread in a different process
T1497.001 antivm_disk_size: Checks the amount of free disk space
T1070 stealth_window: A process created a hidden window
T1497.001 antivm_network_adapters: Checks NIC addresses
T1480 system_default_lang_id_present: Checks the system language
T1027.002 nsis_archive: One of the packages is NSIS archive
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1497.001 antivm_queries_computername: Retrieves the computer name
Credential Access
T1552 infostealer_im: Collects information about installed messengers
T1503 infostealer_browser: Retrieves personal information from local Internet browsers
T1552 infostealer_mail: Collects personal data from local email clients
T1552 infostealer_browser: Retrieves personal information from local Internet browsers
T1552 infostealer_ftp: Collects data from local FTP clients
Discovery
T1497.001 antivm_disk_size: Checks the amount of free disk space
T1497.001 antivm_network_adapters: Checks NIC addresses
T1497.001 antivm_queries_computername: Retrieves the computer name
Collection
T1114 infostealer_mail: Collects personal data from local email clients
Command and Control
T1071.001 network_http: Performs HTTP requests
Other
suricata_alert: Malicious traffic detected
ip_domains: Identifies an IP address using external resources
executes_dropped_exe: Executes dropped exe files
only_exec_in_archive: The archive contains only an executable file
telegram_api: Telegram Messenger API is used
no_graphical_activity: No graphic activity
yara_rules: Static rules
creates_suspended_process: Creates suspended process
creates_exe: Creates executable files in the file system
test_check_service: Starts services
checktokenmembership: Checks user token with CheckTokenMembership call
pe_overlay: PE file contains overlay
Managed XDR