Managed XDR

vtdl_4xs8vfjw (ALPHV) — malware analysis report

File info

Filename
vtdl_4xs8vfjw
File type
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed
File size
3.9 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
bd7f8ba11ab36052abe9cfb20c94e2e2eb0c753f
SHA256
07b929b6deb691f32df01a4fe8b4e96b49cf5192ba40b366d83363beacbf3921
MD5
305775f2e48d14778a64b6d6c932e6cb

Malwares

  • ALPHV

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_upx: The executable file is compressed using UPX
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity

Related reports