Managed XDR

vtdl_1733291623_7bya9qev — malware analysis report

File info

Filename
vtdl_1733291623_7bya9qev
File type
PE32+ executable (GUI) x86-64, for MS Windows
File size
15 MB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
04ee50237521662072d15cb98d664f71ac57a89a
SHA256
d4a7e510253af4d54f3f7568d4a6f0d3c6356a50b7cbf61616e63d376460eba9
MD5
3ab30230eaf3303962e97e9b8c79ecd9

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.002 antisandbox_mouse_hook: Installs a hook to monitor mouse movements
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1056.001 infostealer_keylogger: Keylogger (intercepts keystrokes)

Discovery

T1497.002 antisandbox_mouse_hook: Installs a hook to monitor mouse movements

Collection

T1056.001 infostealer_keylogger: Keylogger (intercepts keystrokes)

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
has_pdb: This executable file has a PDB path
creates_exe: Creates executable files in the file system
test_check_service: Starts services