VTI Score
100 / 100
|
|
VTI Database Version | 2.6 |
VTI Rule Match Count | 17 |
VTI Rule Type | Documents |
Injection | Write into memory of a process running from a created or modified executable |
|
|
"c:\users\kft6utqw\appdata\local\temp\heidi.exe" modifies memory of "c:\users\kft6utqw\appdata\local\temp\heidi.exe"
|
|||
Injection | Modify control flow of a process running from a created or modified executable |
|
|
"c:\users\kft6utqw\appdata\local\temp\heidi.exe" alters context of "c:\users\kft6utqw\appdata\local\temp\heidi.exe"
|
|||
Network | Download file |
|
|
Download file from "http://kdotraky.com/kat/val.exe" to "c:\users\kft6utqw\appdata\local\temp\heidi.exe".
|
|||
Process | Create process |
|
|
Create process "C:\Users\kFT6uTQW\AppData\Local\Temp\heidi.exe".
|
|||
Anti Analysis | Try to detect debugger |
|
|
Check via API "NtQueryInformationProcess".
|
|||
File System | Handle with malicious files |
|
|
File "c:\users\kft6utqw\appdata\local\microsoft\windows\temporary internet files\content.ie5\x9ohk109\val[1].exe" is a known malicious file.
|
|||
Network | Reputation URL lookup |
|
|
URL "http://kdotraky.com/kat/val.exe" is known as malicious URL.
|
|||
URL "kdotraky.com/temp/Panel/five/fre.php" is known as malicious URL.
|
|||
Network | Download data |
|
|
URL "http://kdotraky.com/kat/val.exe".
|
|||
URL "kdotraky.com/temp/Panel/five/fre.php".
|
|||
Browser | Read data related to saved browser credentials |
|
|
Read saved credentials for "Google Chrome".
|
|||
Network | Perform DNS request |
|
|
Resolve host name "kdotraky.com".
|
|||
Resolve host name "ÅÐÐÑÐЯÐÐÑ".
|
|||
Network | Connect to remote host |
|
|
Outgoing TCP connection to host "101.99.75.184:80".
|
|||
Information Stealing | Read system data |
|
|
Read the cryptographic machine GUID from registry.
|
|||
Network | Connect to HTTP server |
|
|
URL "kdotraky.com/temp/Panel/five/fre.php".
|
|||
PE | Drop PE file |
|
|
Drop file "c:\users\kft6utqw\appdata\local\microsoft\windows\temporary internet files\content.ie5\x9ohk109\val[1].exe".
|
|||
Process | Create system object |
|
|
Create mutex with name "73EE9CC98E5412EEF2B9A336".
|