Managed XDR

vtdl_1740493312_8bj399cb — malware analysis report

File info

Filename
vtdl_1740493312_8bj399cb
File type
SMTP mail, UTF-8 Unicode text, with CRLF line terminators
File size
221.5 KB
First seen
Last seen

Environment

w10/x86 en

Hashes

SHA1
d8bb3eb6d05af84cb7cf635d9f02f123655b354a
SHA256
6b53f7b3ddf676c138d0c76c4d3b525f488582c073962e7d722e4ae23384f3b1
MD5
774df89717b53937ddc617b5c5eaba80

Signatures

Privilege Escalation

T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Command and Control

T1102.003 cloud_discord: Connects to cloud services of Discord (potentially for malicious payload delivery)

Other

no_graphical_activity: No graphic activity
dotnet_suspicious_resources_names: Dotnet program has suspicious resources names
dotnet_obfuscated: Dotnet program is potentially obfuscated
get_policy_info: Retrieves information about a Policy object
suspicious_network_port: Performs TCP or UDP request to non-standard port
checktokenmembership: Checks user token with CheckTokenMembership call
dotnet_suspicious_entrypoint: Dotnet program has suspicious entrypoint
suricata_alert: Malicious traffic detected
yara_rules: Static rules
dotnet_downloader_possible_network_problem: Dotnet program possibly has network problem