Managed XDR

vtdl_ev99ey20 — malware analysis report

File info

Filename
vtdl_ev99ey20
File type
PE32 executable (GUI) Intel 80386, for MS Windows
File size
584 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
346bd8c2de0ed007a54a54782fe6fa5ed4ee798f
SHA256
46b6bf80c512f2cfa6994e84d0bc020f784fe4948fc56a940a31a1984a1f4469
MD5
38d67275ea58ed867f7276ad4fd6732f

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_vmprotect: Executable file is likely compressed using VMProtect
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
has_pdb: This executable file has a PDB path