Managed XDR

vtdl_1784790872_747on7ok (Remcos) — malware analysis report

File info

Filename
vtdl_1784790872_747on7ok
File type
SMTP mail, UTF-8 Unicode text, with CRLF line terminators
File size
2.5 MB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
4affa6d618e65374270d621006b806bb0c127e32
SHA256
39188b79c91ccd154b904a88ec740ec85a594a8c0b0c4dd08e271759dd5f2922
MD5
a1b5434de4786852d961a5074e9e02d7

Malwares

  • Remcos

Signatures

Initial Access

T1192 html_urls: HTML-document downloads a file

Execution

T1204.002 mimics_extension: Attempts to mimic the file extension

Persistence

T1574 dropper_dll: Creates DLL, which is then loaded into the process

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1574 dropper_dll: Creates DLL, which is then loaded into the process

Defense Evasion

T1027.002 decompress_pefile: Unpacks a PE file into memory
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1564.001 stealth_file: Creates hidden or system files
T1036 mimics_extension: Attempts to mimic the file extension
T1140 decompress_pefile: Unpacks a PE file into memory
T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1555.004 windows_credential_manager: Acquire credentials from the Windows Credential Manager

Discovery

T1033 recon_beacon: The process has sent information about the computer over the network
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization

Command and Control

T1071.001 recon_beacon: The process has sent information about the computer over the network
T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp

Other

networkdyndns_checkip: Connects to a Dynamic DNS domain
network_bind: Starts servers listening at None
creates_exe: Creates executable files in the file system
no_graphical_activity: No graphic activity
valid_authenticode: The digital signature has been verified
has_pdb: This executable file has a PDB path
origin_langid: Unconventional language of the executable file
suspicious_network_port: Performs TCP or UDP request to non-standard port
test_check_service: Starts services
pe_overlay: PE file contains overlay
yara_rules: Static rules

Related reports