Managed XDR

vtdl_1763189013_irei49ig (DarkComet) — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl_1763189013_irei49ig
Тип файла
PE32 executable (GUI) Intel 80386, for MS Windows
Размер файла
1.9 MB
Первое обнаружение
Последнее обнаружение

Окружение

w10/x86 en

Хеши

SHA1
57bdaf7a22cca43be79e47c4bd7463a9da0f92c3
SHA256
7ded2036d6cd880a09df1fced4eda66f5078e9615e1faeb358004fdc823a1b00
MD5
2699e24749b345c8f4a7139bedcabc6a

Вредоносное ПО

  • DarkComet

Сигнатуры

Privilege Escalation

T1055.002 inject_write_pe: Writes PE file to another process's memory
T1055.012 injection_runpe: Injects code into another process
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1055.002 inject_write_pe: Writes PE file to another process's memory
T1055.012 injection_runpe: Injects code into another process
T1027.002 packer_polymorphic: Creates a modified copy of itself
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1480 system_default_lang_id_present: Checks the system language
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1027.002 packer_vb: The executable file is packed using VB
T1070 stealth_window: A process created a hidden window

Discovery

T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1016 system_network_configuration_discovery: System network configuration discovery detected
T1082 recon_systeminfo: Collects system information (ipconfig, netstat, systeminfo, net)

Collection

T1115 checks_clipboard: Monitors clipboard data

Other

yara_rules: Static rules
networkdyndns_checkip: Connects to a Dynamic DNS domain
static_pe_anomaly: The PE file structure contains anomalies
rat_fynloski: Fynloski/DarkComet indicators detected
creates_exe: Creates executable files in the file system
dns_without_resolve: DNS query without a response
suspicious_process: Spawns a suspicious process
executes_dropped_exe: Executes dropped exe files
process_crashed: One of the processes has failed
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
break_limit_exceeded: Warning: function calls limit has been exceeded
writes_data: Writes big amount of data to disk
pe_overlay: PE file contains overlay
suricata_alert: Malicious traffic detected

Похожие отчёты

Managed XDR