Managed XDR

vtdl_j8dywtfq — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl_j8dywtfq
Тип файла
Zip archive data, at least v2.0 to extract
Размер файла
3.3 MB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x64 en

Хеши

SHA1
a087f16e97c437eda116ed010486f6064be58918
SHA256
c4e6e8de0fddf8eb4688ca86e1c6e52d1c6b33d8e2fd8e1c647be8b2ac63b158
MD5
ddce5fbbd59abcf856a32f4ed2377f85

Сигнатуры

Initial Access

T1192 html_urls: HTML-document downloads a file

Privilege Escalation

T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1070 stealth_window: A process created a hidden window
T1027.001 static_overlay_padding: Overlay contents padding
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1555.003 cookie_files: Accesses cookie files
T1056.001 infostealer_keylogger: Keylogger (intercepts keystrokes)
T1552 cookie_files: Accesses cookie files

Discovery

T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1057 process_interest: Enumerates processes

Collection

T1056.001 infostealer_keylogger: Keylogger (intercepts keystrokes)

Command and Control

T1071.001 network_http: Performs HTTP requests
T1102.003 references_github: Contains links to cloud services of Github (potentially for malicious payload delivery)
T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp
T1071.001 wininet_openurl: Performs HTTP/HTTPS-requests using InternetOpenUrl

Other

modifies_certs: Attempts to generate or modify system certificates
create_rpc_bindings: Creates RPC connection
net_dumps_in_native: .Net dumps have been found in native PE
require_administrator: Requests administrator privileges
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
pe_overlay: PE file contains overlay