Managed XDR

vtdl__b_6tlem — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl__b_6tlem
Тип файла
PE32 executable (GUI) Intel 80386, for MS Windows, RAR self-extracting archive
Размер файла
83.2 MB
Первое обнаружение
Последнее обнаружение

Окружение

w10/x64 en

Хеши

SHA1
c9c6d996b8db6d08663f082a2a98d191d14f4723
SHA256
42b4eba14ba4baa9a5ae29fdd34d0d367195a618b1cf8677960538af5d425f32
MD5
dc794fcaf1186d5621f1d85c802fe6a9

Сигнатуры

Execution

T1053.005 creates_tasks: Creates a delayed task using Task Scheduler
T1053.005 persistence_autorun: Makes itself run automatically on Windows startup
T1059.007 bad_js: Suspicious Javascript file
T1059.003 executes_dropped_cmd: Executes dropped batch files
T1059.006 drops_python_dll: Drops python dll

Persistence

T1053.005 creates_tasks: Creates a delayed task using Task Scheduler
T1053.005 persistence_autorun: Makes itself run automatically on Windows startup
T1547.004 persistence_autorun: Makes itself run automatically on Windows startup
T1574.001 dll_hijacking: Indicators of DLL Hijacking vulnerability exploitation detected (creates a typical file)
T1574.011 persistence_services: Modifies Services registry key
T1543.003 persistence_services: Modifies Services registry key
T1574 dropper_dll: Creates DLL, which is then loaded into the process

Privilege Escalation

T1053.005 creates_tasks: Creates a delayed task using Task Scheduler
T1548.002 uac_bypass_mocking_dir: UAC bypass with the use of mocking directory
T1053.005 persistence_autorun: Makes itself run automatically on Windows startup
T1547.004 persistence_autorun: Makes itself run automatically on Windows startup
T1574.001 dll_hijacking: Indicators of DLL Hijacking vulnerability exploitation detected (creates a typical file)
T1574.011 persistence_services: Modifies Services registry key
T1543.003 persistence_services: Modifies Services registry key
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1574 dropper_dll: Creates DLL, which is then loaded into the process

Defense Evasion

T1548.002 uac_bypass_mocking_dir: UAC bypass with the use of mocking directory
T1564.001 hides_original_file: Makes original executable file hidden
T1574.001 dll_hijacking: Indicators of DLL Hijacking vulnerability exploitation detected (creates a typical file)
T1564.001 stealth_file: Creates hidden or system files
T1497.001 antivm_disk_size: Checks the amount of free disk space
T1574.011 persistence_services: Modifies Services registry key
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1574 dropper_dll: Creates DLL, which is then loaded into the process

Credential Access

T1555.004 windows_credential_manager: Acquire credentials from the Windows Credential Manager
T1056.001 infostealer_keylogger: Keylogger (intercepts keystrokes)

Discovery

T1497.001 antivm_disk_size: Checks the amount of free disk space

Collection

T1056.001 infostealer_keylogger: Keylogger (intercepts keystrokes)

Impact

T1529 shutdown_system: Shuts the system down

Other

yara_rules: Static rules
ransomware_bcdedit: Runs bcdedit commands specific to ransomware
creates_exe: Creates executable files in the file system
executes_dropped_exe: Executes dropped exe files
create_rpc_bindings: Creates RPC connection
creates_suspended_process: Creates suspended process
message_box: Displays a message
error_drawtext: An error occured while executing the file
test_check_service: Starts services
checktokenmembership: Checks user token with CheckTokenMembership call
pe_overlay: PE file contains overlay
static_big_overlay: Executable file contains an enormously big overlay