Managed XDR

vtdl_rrr6jyyo — malware analysis report

File info

Filename
vtdl_rrr6jyyo
File type
PE32 executable (GUI) Intel 80386, for MS Windows
File size
4.2 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
ddee8808f5741415bb3b3f35e7e634609cd2b972
SHA256
f36b03e181cc9178dc2adce3065895509874a93856cf3c373a57e8b20b517254
MD5
83ad56eb068bb0e69569d25823c130bc

Signatures

Defense Evasion

T1036.001 invalid_authenticode: Digital signature of the executable file has failed the verification
T1027.002 packer_entropy: Probably contains compressed or encrypted data

Command and Control

T1102.003 cloud_discord: Connects to cloud services of Discord (potentially for malicious payload delivery)

Other

ip_domains: Identifies an IP address using external resources
dns_without_resolve: DNS query without a response
has_pdb: This executable file has a PDB path
origin_langid: Unconventional language of the executable file
suspicious_network_port: Performs TCP or UDP request to non-standard port
pe_overlay: PE file contains overlay
suricata_alert: Malicious traffic detected