Managed XDR

vtdl_fig50yl3 — malware analysis report

File info

Filename
vtdl_fig50yl3
File type
RAR archive data, v4, os: Win32
File size
333.6 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
0d7cda36de1722464201bb93888708c8aa421b67
SHA256
62997ecbbb2720245ae9d35ca942e94ee109f3548114b464eb2475ad2b4ff4b4
MD5
081690a3ae6cd42457cc40362386b2a6

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1057 process_interest: Enumerates processes

Other

yara_rules: Static rules
static_pe_anomaly: The PE file structure contains anomalies
has_pdb: This executable file has a PDB path
origin_langid: Unconventional language of the executable file