Managed XDR

vtdl_ss_k55q7 — malware analysis report

File info

Filename
vtdl_ss_k55q7
File type
Zip archive data, at least v2.0 to extract
File size
12.6 MB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
1699613dc90afdf3f0f3a0cfdbe60a9f264a0116
SHA256
c5483d5b4d0d9b09beacb33f8358d7cd3a554bd8edeb7d6ba9935e46fba7184b
MD5
d8d24935d052b70041db44bcae62c0ad

Signatures

Persistence

T1574 dropper_dll: Creates DLL, which is then loaded into the process

Privilege Escalation

T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
has_pdb: This executable file has a PDB path
test_check_service: Starts services
pe_overlay: PE file contains overlay