Managed XDR

vtdl_1789024493_kpi9sd0_ (Remcos) — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl_1789024493_kpi9sd0_
Тип файла
Composite Document File V2 Document, No summary info
Размер файла
121.5 KB
Первое обнаружение
Последнее обнаружение

Окружение

w10/x64 en

Хеши

SHA1
af5de43218f128a3aa18031f123d4791e361eac3
SHA256
559c556615dc2d9a938c71fc7161bc864f7f9a8aa022253c63e2791c2ef29904
MD5
02c1e35c3af928a00557892885f04a9a

Вредоносное ПО

  • Remcos

Сигнатуры

Execution

T1053.005 creates_tasks: Creates a delayed task using Task Scheduler
T1053.005 persistence_autorun: Makes itself run automatically on Windows startup

Persistence

T1053.005 creates_tasks: Creates a delayed task using Task Scheduler
T1053.005 persistence_autorun: Makes itself run automatically on Windows startup

Privilege Escalation

T1055.002 inject_write_pe: Writes PE file to another process's memory
T1055.012 injection_runpe: Injects code into another process
T1053.005 creates_tasks: Creates a delayed task using Task Scheduler
T1053.005 persistence_autorun: Makes itself run automatically on Windows startup
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1055.002 inject_write_pe: Writes PE file to another process's memory
T1055.012 injection_runpe: Injects code into another process
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1027.004 compiles_code: Compiles C# code
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1027.001 static_overlay_padding: Overlay contents padding

Credential Access

T1555.004 windows_credential_manager: Acquire credentials from the Windows Credential Manager

Discovery

T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers

Command and Control

T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp
T1102.003 references_google: Contains links to cloud services of Google (potentially for malicious payload delivery)

Other

yara_rules: Static rules
ce_info: Remcos Configuration Data found
unpacker_wrong_base: Possibly, an error occurred in the file unpacker
copies_self: Creates a copy of itself
network_bind: Starts servers listening at None
creates_exe: Creates executable files in the file system
dotnet_obfuscated: Dotnet program is potentially obfuscated
process_crashed: One of the processes has failed
dotnet_suspicious_resources_names: Dotnet program has suspicious resources names
dotnet_suspicious_module_name: Dotnet program has suspicious module name
creates_suspended_process: Creates suspended process
static_compression_ratio: Very high compression ratio of a file
suspicious_network_port: Performs TCP or UDP request to non-standard port
test_check_service: Starts services
checktokenmembership: Checks user token with CheckTokenMembership call
writes_data: Writes big amount of data to disk
pe_overlay: PE file contains overlay
static_big_overlay: Executable file contains an enormously big overlay

Похожие отчёты