Managed XDR

vtdl_k5rntsff — malware analysis report

File info

Filename
vtdl_k5rntsff
File type
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
File size
604 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
65ab24abe25693af961cc40ae3adf1ad720e3d3d
SHA256
08bfa26652f2d68b674cf19e0ff8703219dcaa71d304ff2a6cb19a9c6670f480
MD5
8d900456a40033e37ef965eaf60fd5a9

Signatures

Execution

T1559 message_box: Displays a message

Persistence

T1574 dropper_dll: Creates DLL, which is then loaded into the process

Privilege Escalation

T1574 dropper_dll: Creates DLL, which is then loaded into the process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1574 dropper_dll: Creates DLL, which is then loaded into the process

Other

yara_rules: Static rules