Managed XDR

vtdl_jpg28egf — malware analysis report

File info

Filename
vtdl_jpg28egf
File type
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Mon Feb 15 14:32:11 2021, mtime=Tue Jan 18 20:32:26 2022, atime=Mon Feb 15 14:32:11 2021, length=236544, window=hide
File size
2 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
9c3d21142fb5af719d3f9237a6425c3d92f2a979
SHA256
9e7d780ca726e68e409c1e4fff2a73b4ed282e73321c7b8a34bb175c58b8dfd1
MD5
22cbc2269a446f53b37993e9192ff1fe

Signatures

Execution

T1204 suspicious_lnk: LNK file with suspicious content
T1059.001 url_cmdline: Cmdline of process contains URL
T1059.003 url_cmdline: Cmdline of process contains URL

Defense Evasion

T1218 suspicious_cmdline: Executes a suspicious command

Credential Access

T1552 cookie_files: Accesses cookie files
T1555.003 cookie_files: Accesses cookie files

Command and Control

T1071.001 network_http: Performs HTTP requests
T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp
T1071.001 wininet_https: Performs HTTP/HTTPS requests using WinInet

Other

unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
yara_rules: Static rules