Managed XDR

vtdl_9dq62mpf — malware analysis report

File info

Filename
vtdl_9dq62mpf
File type
Zip archive data, at least v2.0 to extract
File size
1.3 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
d3dce1b8a58480ed8292b5a7c5fb8bea0c4588b6
SHA256
92e2c50185066daeaeec957621b4830164232c79d856b3b4d23c3004c5f2f50f
MD5
9ca5dcb9e95a3442f33decec50b7578b

Signatures

Execution

T1204.002 mimics_extension: Attempts to mimic the file extension
T1059.005 obfuscated_vbs: Detected obfuscated VBS
T1047 has_wmi: Executes one or several WMI requests

Persistence

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup

Privilege Escalation

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1055 injection_failed: The attempt to inject into a process has failed

Defense Evasion

T1036 mimics_extension: Attempts to mimic the file extension
T1562.004 firewall_add_rule: Modifies Firewall rules
T1027 obfuscated_vbs: Detected obfuscated VBS
T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1055 injection_failed: The attempt to inject into a process has failed

Credential Access

T1056.001 infostealer_keylogger: Keylogger (intercepts keystrokes)

Discovery

T1082 uses_windows_utilities: Uses Windows utilities for basic Windows functionality
T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1082 reads_csrss: Attempts to read csrss.exe memory

Collection

T1560.001 archive_via_utility: Detected archiving data via utility
T1056.001 infostealer_keylogger: Keylogger (intercepts keystrokes)

Impact

T1529 shutdown_system: Shuts the system down

Other

yara_rules: Static rules
creates_exe: Creates executable files in the file system
creates_suspended_process: Creates suspended process
checktokenmembership: Checks user token with CheckTokenMembership call