Managed XDR

vtdl_lwbqnkxr — malware analysis report

File info

Filename
vtdl_lwbqnkxr
File type
Rich Text Format data, unknown version
File size
251 Bytes
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
85c92028c51ac24137925dc03c450a43bc8b0f6f
SHA256
cb87c016ed026126f07ebe11a9035692e0536517e76d4615d8bf41d3516f6426
MD5
55ba3c62b4689721c58272dea9de7ece

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antivm_queries_computername: Retrieves the computer name

Other

yara_rules: Static rules
get_policy_info: Retrieves information about a Policy object
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card