Managed XDR

vtdl_1790150635_b0turk3a (Bazar Loader) — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl_1790150635_b0turk3a
Тип файла
PE32+ executable (GUI) x86-64, for MS Windows
Размер файла
127 KB
Первое обнаружение
Последнее обнаружение

Окружение

w10/x64 en

Хеши

SHA1
7ccc6f9de22f3e0b9b58eedcb811947b7bf7a5e5
SHA256
0a8777991cc62ec5ea829f45a011b60f2e7c8777e26cc5b3a8705fa8f04169b3
MD5
c12bfedf1da3f1cb20e16077e7b6f8c0

Вредоносное ПО

  • Bazar Loader

Сигнатуры

Execution

T1047 antivm_wmi: Uses WMI to detect virtual environment
T1047 has_wmi: Executes one or several WMI requests

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.001 antivm_wmi: Uses WMI to detect virtual environment
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization
T1497.002 antivm_usbstor: Reads information about usbdevices from regkey
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1555.004 windows_credential_manager: Acquire credentials from the Windows Credential Manager

Discovery

T1497.001 antivm_wmi: Uses WMI to detect virtual environment
T1082 has_wmi: Executes one or several WMI requests
T1057 has_wmi: Executes one or several WMI requests
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization
T1497.002 antivm_usbstor: Reads information about usbdevices from regkey

Command and Control

T1071 internet_security_options: Sets Internet connections options that are not secure
T1032 internet_security_options: Sets Internet connections options that are not secure
T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp
T1071.001 wininet_https: Performs HTTP/HTTPS requests using WinInet

Other

yara_rules: Static rules
network_bind: Starts servers listening at None
suspicious_network_port: Performs TCP or UDP request to non-standard port
test_check_service: Starts services

Похожие отчёты