Managed XDR

vtdl_6fn55adv — malware analysis report

File info

Filename
vtdl_6fn55adv
File type
RAR archive data, v5
File size
5.4 MB
First seen
Last seen

Environment

win7/x64 en

Hashes

SHA1
4553f9a71e4b87e272e82484f517b90a92ecb1cb
SHA256
fe43f36873801492397fa9c9b55643a14440557502b168a2d97b0ecc2f448366
MD5
25d42de2e9c9e942af9684e27609c1a9

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_vmprotect: Executable file is likely compressed using VMProtect
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1027.002 packer_entropy: Probably contains compressed or encrypted data

Discovery

T1057 process_interest: Enumerates processes

Other

yara_rules: Static rules
only_exec_in_archive: The archive contains only an executable file
process_crashed: One of the processes has failed
no_graphical_activity: No graphic activity
test_check_service: Starts services