Managed XDR

vtdl_br4bne5e — malware analysis report

File info

Filename
vtdl_br4bne5e
File type
Zip archive data, at least v2.0 to extract
File size
37.1 MB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
9d5f5fb19bfee3312b3ca2a5909f88b4ab04373e
SHA256
47092049bb428d3d213702c2b58090f8f0d3754a2b5ddaea45acd7119557b888
MD5
560a62fb1bb17b3ab042548d77ae139f

Signatures

Execution

T1047 has_wmi: Executes one or several WMI requests
T1059.003 executes_dropped_cmd: Executes dropped batch files
T1059.003 suspicious_batch: Suspicious batch

Persistence

T1574 dropper_dll: Creates DLL, which is then loaded into the process

Privilege Escalation

T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1055 injection_failed: The attempt to inject into a process has failed
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1497.001 antivm_generic_cpu: Checks the CPU name, possibly for anti-virtualization
T1070.001 wevtutil_clear_log: Clears event log using wevtutil
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1497.003 antisandbox_sleep_utilities: Uses Windows utilities for pausing the execution
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1027.002 nsis_archive: One of the packages is NSIS archive
T1480 system_default_lang_id_present: Checks the system language
T1055 injection_failed: The attempt to inject into a process has failed

Discovery

T1497.001 antivm_generic_cpu: Checks the CPU name, possibly for anti-virtualization
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1497.003 antisandbox_sleep_utilities: Uses Windows utilities for pausing the execution
T1518 locates_browser: Attempts to identify where browsers are installed
T1082 reads_csrss: Attempts to read csrss.exe memory
T1016.001 system_network_configuration_discovery: System network configuration discovery detected

Command and Control

T1102.003 references_google: Contains links to cloud services of Google (potentially for malicious payload delivery)
T1102.003 references_yandex: Contains links to cloud services of Yandex (potentially for malicious payload delivery)

Impact

T1486 ransomware_windows_possible: Ransomware indicators detected (possible ransom window creation)
T1489 stops_service: Stops Windows services
T1489 net_stop: Stops services through the use of net stop

Other

creates_many_processes: Spawns a lot of processes (over 70)
creates_exe: Creates executable files in the file system
codepage: Checks the system code page
create_rpc_bindings: Creates RPC connection
require_administrator: Requests administrator privileges
has_pdb: This executable file has a PDB path
creates_suspended_process: Creates suspended process
break_limit_exceeded: Warning: function calls limit has been exceeded
message_box: Displays a message
msi_has_custom_action: MSI file contains custom action
suspicious_network_port: Performs TCP or UDP request to non-standard port
test_check_service: Starts services
office_links: Office file contains external links
checktokenmembership: Checks user token with CheckTokenMembership call
pe_overlay: PE file contains overlay
many_files_in_archive: The archive contains more than 5 files