Managed XDR

vtdl_1791502738_zd2w7udk — malware analysis report

File info

Filename
vtdl_1791502738_zd2w7udk
File type
MS Windows shortcut, Item id list present, Has Working directory, Has command line arguments, Icon number=0, ctime=Thu Oct 8 03:33:37 2026, mtime=Thu Oct 8 03:33:37 2026, atime=Thu Oct 8 03:33:37 2026, length=0, window=hidenormalshowminimized
File size
133.3 KB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
f24d2126e395d3d6ecfc6cf11ee64c5ce5b61097
SHA256
0879ba324263d0fd6a1159267f9dcacabeb3f418e3a5b8a43ae9f57f7570e01f
MD5
80898d3b16de3f52b18c73d309b15c72

Signatures

Execution

T1047 antivm_wmi: Uses WMI to detect virtual environment
T1047 has_wmi: Executes one or several WMI requests

Defense Evasion

T1497.001 antivm_wmi: Uses WMI to detect virtual environment
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization
T1497.002 antivm_usbstor: Reads information about usbdevices from regkey
T1070.004 self_removal_command: Executes command to delete itself

Credential Access

T1555.004 windows_credential_manager: Acquire credentials from the Windows Credential Manager

Discovery

T1497.001 antivm_wmi: Uses WMI to detect virtual environment
T1057 has_wmi: Executes one or several WMI requests
T1082 has_wmi: Executes one or several WMI requests
T1518 locates_browser: Attempts to identify where browsers are installed
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization
T1497.002 antivm_usbstor: Reads information about usbdevices from regkey

Command and Control

T1102.003 cloud_dropbox: Connects to cloud services of Dropbox (potentially for malicious payload delivery)
T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp

Other

network_bind: Starts servers listening at None
opens_document: Opens office documents
creates_exe: Creates executable files in the file system
creates_doc: Creates (office) documents in the file system
creates_suspended_process: Creates suspended process
suspicious_network_port: Performs TCP or UDP request to non-standard port
test_check_service: Starts services
yara_rules: Static rules