Managed XDR

vtdl_zw8qgpg0 — malware analysis report

File info

Filename
vtdl_zw8qgpg0
File type
PE32 executable (GUI) Intel 80386, for MS Windows
File size
13 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
549333064bb5d8f0bf1db806387b0da2796e64b2
SHA256
e900660474e14db3a3528455aa3aa75c8cb05d47bbda2e59f4e7b178f3a6256c
MD5
60e372f476f0845344c656b0a185ce8d

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
static_pe_duplicate_sections: The PE file structure contains anomalies: duplicate section names
no_graphical_activity: No graphic activity
require_administrator: Requests administrator privileges
origin_langid: Unconventional language of the executable file