Managed XDR

vtdl_dvwqlm67 (RedCurl.SimpleDownloader, ) — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl_dvwqlm67
Тип файла
ISO 9660 CD-ROM filesystem data 'OZON.RU'
Размер файла
2 MB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
2879784ff893812213e11d712679e3fb006ac99e
SHA256
d2e1bb8ababa336297a3c7ffc4882b2a33659ed6c549c6a0df8a5ed84afd7e3c
MD5
00dc05c9a887a972fe6040904ce34937

Вредоносное ПО

  • RedCurl.SimpleDownloader

Сигнатуры

Execution

T1204 suspicious_lnk: LNK file with suspicious content

Persistence

T1574 dropper_dll: Creates DLL, which is then loaded into the process

Privilege Escalation

T1574 dropper_dll: Creates DLL, which is then loaded into the process

Defense Evasion

T1574 dropper_dll: Creates DLL, which is then loaded into the process

Credential Access

T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files

Command and Control

T1071.001 network_cnc_http: Suspicious HTTP traffic
T1071.001 network_http: Performs HTTP requests
T1071.001 wininet_https: Performs HTTP/HTTPS requests using WinInet

Other

yara_rules: Static rules
suspicious_process_network: Unusual process network activity detected
unexpected_exception: Unexpected exception
iso_hidden_files: The ISO archive contains hidden directories
creates_suspended_process: Creates suspended process
lnk_exec_in_archive: The archive contains only shortcut an executable file
many_files_in_archive: The archive contains more than 5 files