Managed XDR

vtdl_1789398503_0vwpfrty (Rhadamanthys Stealer) — malware analysis report

File info

Filename
vtdl_1789398503_0vwpfrty
File type
7-zip archive data, version 0.4
File size
267.2 KB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
9b5d8373979923ce10760b8e72ad05bf4141c5e9
SHA256
fb54d625e4d809909115b2749deb63ccb23fb41291009d5c1eaa34b72652d55a
MD5
973a6403606580280450bc9de29b65ce

Malwares

  • Rhadamanthys Stealer

Signatures

Execution

T1047 has_wmi: Executes one or several WMI requests

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497 antidbg_setinformationthread: Attempts to evade debugger using NtSetInformationThread
T1497.001 antivm_vbox_devices: Detects VirtualBox through the presence of a device
T1497.001 antisandbox_file: Attempts to detect a sandbox (checks the file name)
T1497.001 antivm_generic_bios: Checks the BIOS version, possibly for anti-virtualization
T1497.001 antivm_vbox_acpi: Detects virtualization using ACPI
T1497.001 antivm_vbox_keys: Detects VirtualBox through the presence of a registry key
T1497.001 antivm_vbox_files: Detects VirtualBox through the presence of a file
T1497.001 antivm_vmware_keys: Detects VMware through the presence of a registry key
T1497.001 antivm_generic_ide: Checks the presence of IDE drives in the registry, possibly for anti-virtualization
T1497.001 antivm_generic_scsi: Attempts to detect virtualization by SCSI Disk Identifier
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1497 antidbg_writewatch: Checks, if there was an access to a specific memory region (typical behavior for debuggers)
T1497 antidbg_protected_handle: Attempts to close protected handle (may be used to prevent debugging)
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization
T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1027.001 static_overlay_padding: Overlay contents padding

Credential Access

T1555.004 windows_credential_manager: Acquire credentials from the Windows Credential Manager

Discovery

T1497 antidbg_setinformationthread: Attempts to evade debugger using NtSetInformationThread
T1497.001 antivm_vbox_devices: Detects VirtualBox through the presence of a device
T1497.001 antisandbox_file: Attempts to detect a sandbox (checks the file name)
T1497.001 antivm_generic_bios: Checks the BIOS version, possibly for anti-virtualization
T1497.001 antivm_vbox_acpi: Detects virtualization using ACPI
T1497.001 antivm_vbox_keys: Detects VirtualBox through the presence of a registry key
T1497.001 antivm_vbox_files: Detects VirtualBox through the presence of a file
T1497.001 antivm_vmware_keys: Detects VMware through the presence of a registry key
T1497.001 antivm_generic_ide: Checks the presence of IDE drives in the registry, possibly for anti-virtualization
T1497.001 antivm_generic_scsi: Attempts to detect virtualization by SCSI Disk Identifier
T1497 antidbg_writewatch: Checks, if there was an access to a specific memory region (typical behavior for debuggers)
T1497 antidbg_protected_handle: Attempts to close protected handle (may be used to prevent debugging)
T1057 has_wmi: Executes one or several WMI requests
T1057 process_interest: Enumerates processes
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization
T1497.001 antivm_queries_computername: Retrieves the computer name

Command and Control

T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp

Other

yara_rules: Static rules
static_big_overlay: Executable file contains an enormously big overlay
network_bind: Starts servers listening at None
dead_host: Connects to IP addresses that do not respond to requests
network_anomaly: Network anomalies occurred during the analysis
only_exec_in_archive: The archive contains only an executable file
unexpected_exception: Unexpected exception
create_rpc_bindings: Creates RPC connection
static_compression_ratio: Very high compression ratio of a file
suspicious_network_port: Performs TCP or UDP request to non-standard port
test_check_service: Starts services
checktokenmembership: Checks user token with CheckTokenMembership call
pe_overlay: PE file contains overlay

Related reports