Managed XDR

vtdl__e8gquoj — malware analysis report

File info

Filename
vtdl__e8gquoj
File type
MS Windows shortcut, Item id list present, ctime=Fri Sep 27 07:32:04 2024, mtime=Fri Sep 27 07:32:04 2024, atime=Fri Sep 27 07:32:04 2024, length=0, window=hide
File size
1 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
b051aea6aeb5f54cf49cd7f3c588a9a7933292be
SHA256
e78af41f79a468532e7014959dfef8ea90ca42f200804e3bbbd47fc5de9453d5
MD5
aee153e17aa23351e25754e30d301a7b

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process