Managed XDR

vtdl_j2pjxjdy (RedLine Stealer) — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl_j2pjxjdy
Тип файла
RAR archive data, v5
Размер файла
537.7 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x64 en

Хеши

SHA1
5b935645d429d3f39c4f5484d95200aaac8fa1e1
SHA256
229964de8b71e84409e3ba50e38e304181ee508c7ec372dee8d733ae7752609a
MD5
4ba3e81a5a079a3cdb40f24901e20bf0

Вредоносное ПО

  • RedLine Stealer

Сигнатуры

Initial Access

T1192 html_urls: HTML-document downloads a file

Privilege Escalation

T1055.002 inject_write_pe: Writes PE file to another process's memory
T1055.012 injection_runpe: Injects code into another process
T1055 injection_runpe_2: Executes injected code in another process
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1055.002 inject_write_pe: Writes PE file to another process's memory
T1055.012 injection_runpe: Injects code into another process
T1036.001 invalid_authenticode: Digital signature of one or several attached files has failed to be verified
T1055 injection_runpe_2: Executes injected code in another process
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1497 checks_firmware: Attempts to read firmware information (potentially for evasion)
T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497 checks_firmware: Attempts to read firmware information (potentially for evasion)
T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1082 checks_firmware: Attempts to read firmware information (potentially for evasion)

Command and Control

T1102.003 references_discord: Contains links to cloud services of Discord (potentially for malicious payload delivery)

Other

yara_rules: Static rules
ce_info: Redline Configuration Data found
dead_host: Connects to IP addresses that do not respond to requests
creates_suspended_process: Creates suspended process
message_box: Displays a message
get_policy_info: Retrieves information about a Policy object
suspicious_network_port: Performs TCP or UDP request to non-standard port
test_check_service: Starts services
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card
pe_overlay: PE file contains overlay
many_files_in_archive: The archive contains more than 5 files

Похожие отчёты