Managed XDR

vtdl_1751933953_w22baxra — malware analysis report

File info

Filename
vtdl_1751933953_w22baxra
File type
MS Windows shortcut, Item id list present, Points to a file or directory, Has command line arguments, Icon number=3, Archive, ctime=Sun Jan 5 19:06:09 2020, mtime=Sat May 31 01:11:15 2025, atime=Sun Jan 5 19:06:09 2020, length=71168, window=hide
File size
1.6 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
12f316f4be36e907f86ed7ff4ab9748cfebd739c
SHA256
5894e94959da77dff203b326fdc3934ea3c925db7a3addb5d0ffe9846d711f43
MD5
0891c99c3b7a3202956e390b06d06c7c

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1518 locates_browser: Attempts to identify where browsers are installed

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
no_graphical_activity: No graphic activity
creates_suspended_process: Creates suspended process
message_box: Displays a message
get_policy_info: Retrieves information about a Policy object