Managed XDR

vtdl_5b815k_l (Coinminer) — malware analysis report

File info

Filename
vtdl_5b815k_l
File type
PE32+ executable (GUI) x86-64, for MS Windows
File size
39.3 MB
First seen
Last seen

Environment

win7/x64 en

Hashes

SHA1
d0e70c9e97d1eafce827f1d7f34dc9739524a652
SHA256
0349cb60e8c4c2becc5cc272eeb76b32120bb92055804da84a5907aad7b4980c
MD5
4e7956b10cc847038c4a9f482825aa99

Malwares

  • Coinminer

Signatures

Execution

T1059.003 executes_dropped_cmd: Executes dropped batch files

Persistence

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1574 dropper_dll: Creates DLL, which is then loaded into the process

Privilege Escalation

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1564.001 stealth_file: Creates hidden or system files
T1497 antidbg_query_process: Checks if the process is being debugged (ProcessDebugPort)
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1070 stealth_window: A process created a hidden window

Discovery

T1497 antidbg_query_process: Checks if the process is being debugged (ProcessDebugPort)
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1057 process_interest: Enumerates processes
T1135 server_share_info: Retrieves information about each shared resource on a server

Command and Control

T1102.003 cloud_github: Connects to cloud services of Github (potentially for malicious payload delivery)

Other

yara_rules: Static rules
network_bind: Starts servers listening at None, 0.0.0.0:4000
creates_exe: Creates executable files in the file system
unsigned_driver_drop: Sample is not signed and drops a device driver
no_graphical_activity: No graphic activity
create_rpc_bindings: Creates RPC connection
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object
pe_overlay: PE file contains overlay
executes_dropped_exe: Executes dropped exe files
suricata_alert: Malicious traffic detected
static_big_overlay: Executable file contains an enormously big overlay

Related reports