Managed XDR

vtdl_1788742319_irol1xpq — malware analysis report

File info

Filename
vtdl_1788742319_irol1xpq
File type
news or mail, UTF-8 Unicode text, with very long lines, with CRLF, LF line terminators
File size
619.3 KB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
f6e29fb91215e200f4ed04e841a9fac335f3c104
SHA256
0c416d865fa213bbb90e17208853f9a629a24acc8a00edc663e349691cab1aac
MD5
a75781a72fb38c595335e010f4ea78a6

Signatures

Initial Access

T1192 html_urls: HTML-document downloads a file

Execution

T1569.002 persistence_service: Starts newly created service

Persistence

T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1574.011 persistence_services: Modifies Services registry key
T1543.003 persistence_services: Modifies Services registry key
T1543.003 creates_service: Creates a service, that will start automatically

Privilege Escalation

T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1574.011 persistence_services: Modifies Services registry key
T1543.003 persistence_services: Modifies Services registry key
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1543.003 creates_service: Creates a service, that will start automatically

Defense Evasion

T1497.001 antivm_generic_services: Enumerates services, possibly for anti-virtualization
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1036.001 invalid_authenticode: Digital signature of the executable file has failed the verification
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1574.011 persistence_services: Modifies Services registry key
T1497 evasion_diskenum: Sandbox evasion using enumeration of partitions
T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antivm_generic_services: Enumerates services, possibly for anti-virtualization
T1518 locates_browser: Attempts to identify where browsers are installed
T1497 evasion_diskenum: Sandbox evasion using enumeration of partitions
T1497.001 antivm_queries_computername: Retrieves the computer name
T1135 server_share_info: Retrieves information about each shared resource on a server

Impact

T1489 change_service_config: Stops services via ChangeServiceConfig
T1489 net_stop: Stops services through the use of net stop

Other

accesses_mailslot: Performs a Mailslot ping, possibly used to get Domain Controller information
driver_load: Loads a driver
creates_exe: Creates executable files in the file system
suspicious_process_network: Unusual process network activity detected
creates_doc: Creates (office) documents in the file system
create_rpc_bindings: Creates RPC connection
creates_suspended_process: Creates suspended process
msi_has_custom_action: MSI file contains custom action
creates_in_programdata: Creates files in the ProgramData directory
suspicious_network_port: Performs TCP or UDP request to non-standard port
test_check_service: Starts services
yara_rules: Static rules