Managed XDR

vtdl_64uynn0y — malware analysis report

File info

Filename
vtdl_64uynn0y
File type
CDFV2 Microsoft Outlook Message
File size
684.5 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
8ae43d9a7bcdc238e41b3f61a91f3f26eb31473c
SHA256
367d4cd24ffce7fc23e8c5c9e2ef414f7bc53f1f6a65f2d82c3feaa10c23132b
MD5
fa2f2b172da0aa4500037f638f96d9da

Signatures

Execution

T1059 autoit: AutoIt script execution detected

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1027.002 packer_upx: The executable file is compressed using UPX
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

creates_many_processes: Spawns a lot of processes (over 70)
no_graphical_activity: No graphic activity
yara_rules: Static rules