Managed XDR

vtdl_cdrffdz3 (CryptBot, RedLine Stealer) — malware analysis report

File info

Filename
vtdl_cdrffdz3
File type
PE32 executable (GUI) Intel 80386, for MS Windows
File size
413.5 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
18a734b02f831bddd50ec8d18e36c9e1c374b21a
SHA256
951c8b4d341ab0a43cad2023ee616d2b622427d34fd4abd0d8dbf84ca42969cd
MD5
2ab27db2b139212cca0d61efaadb7687

Malwares

  • CryptBot
  • RedLine Stealer

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Other

yara_rules: Static rules
dns_without_resolve: DNS query without a response
no_graphical_activity: No graphic activity
has_pdb: This executable file has a PDB path
get_policy_info: Retrieves information about a Policy object

Related reports