Managed XDR

vtdl_acaj4ar5 — malware analysis report

File info

Filename
vtdl_acaj4ar5
File type
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Sun Mar 10 19:10:48 2024, mtime=Sun Mar 10 19:10:48 2024, atime=Sun Mar 10 19:10:48 2024, length=1254616, window=hide
File size
932 Bytes
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
d9f722d2119928822f2266ff3abf49417e10e18d
SHA256
94f24645df7bffab4774737166b79c8e5a25f0a58736201d4a44299bc42c99d7
MD5
523e028fc9c7232908641695c318c129

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object