Managed XDR

vtdl_1730823130_5hkccccz — malware analysis report

File info

Filename
vtdl_1730823130_5hkccccz
File type
PE32 executable (GUI) Intel 80386, for MS Windows
File size
3.8 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
55416d33f311febafefc4e9abd213eaa65d77d47
SHA256
6a9451b024fb724c819a3ce1edcbb1b100b81bb3d0c9e342ff1485816e3f7c3e
MD5
4b17c53a318bda5b17cec374de22b917

Signatures

Persistence

T1574 dropper_dll: Creates DLL, which is then loaded into the process

Privilege Escalation

T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 unnamed_memory_regions_contains_pe: One or several unnamed memory regions are PE files
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1027.002 packer_aspack: Executable file is packed with ASPack
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Other

yara_rules: Static rules
network_bind: Starts servers listening at 127.0.0.1:2143, 127.3.12.242:8111, 127.3.12.242:8112, 127.3.12.242:8113, 127.3.12.242:8114, 127.3.12.242:8115, 127.3.12.242:8116, 127.3.12.242:8117, 127.3.12.242:8118, 127.3.12.240:8536, 127.3.12.240:8537, 127.3.12.240:5841, 127.3.12.240:5842, 127.3.12.240:8174, 127.3.12.240:8175, 127.3.12.240:8121, 127.3.12.240:8122, 127.3.12.240:8322, 127.3.12.240:8323, 127.3.12.240:8522, 127.3.12.240:8523, 127.3.12.242:8181, 127.3.12.242:8182, 127.3.12.242:8183, 127.3.12.242:8184, 127.3.12.242:8185, 127.3.12.242:8186, 127.3.12.242:8187, 127.3.12.242:8188, 127.3.12.242:9600, 127.3.12.242:9601, 127.3.12.242:9603, 127.3.12.242:9602, 127.3.12.242:9604, 127.3.12.242:9605, 127.3.12.242:9606, 127.3.12.242:9607, 127.3.12.242:9608, 127.3.12.242:9609, 127.3.12.242:9610, 127.3.12.242:9011, 127.3.12.242:9611, 127.3.12.242:9612, 127.3.12.242:9613, 127.3.12.242:9614
creates_exe: Creates executable files in the file system
process_crashed: One of the processes has failed
no_graphical_activity: No graphic activity
require_administrator: Requests administrator privileges
message_box: Displays a message
test_check_service: Starts services
suricata_alert: Malicious traffic detected