Managed XDR

vtdl_bizjusl5 (Cerber) — malware analysis report

File info

Filename
vtdl_bizjusl5
File type
PE32 executable (GUI) Intel 80386, for MS Windows
File size
129.3 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
0182149b302e61f6de5ccf26ba2b100fb04e55f5
SHA256
ff983bd6a13a2929ddf782a1fac846b89d1009c53ab275d7d09b1c1b11354e8f
MD5
7beecb3f74f52564fbbca25be2348d08

Malwares

  • Cerber

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
pe_overlay: PE file contains overlay

Related reports