Managed XDR

vtdl_v7vy025o — malware analysis report

File info

Filename
vtdl_v7vy025o
File type
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
File size
4.9 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
19b53166015133b157ec64fbd7951adc74042e0c
SHA256
fcf1771a3afa0fa6984b2462e9d97b2556d5a071447e308ec9a118776ad9cec9
MD5
d99ec41cc848d0b403374c47ffbacd25

Signatures

Persistence

T1574 dropper_dll: Creates DLL, which is then loaded into the process

Privilege Escalation

T1574 dropper_dll: Creates DLL, which is then loaded into the process

Defense Evasion

T1036.001 invalid_authenticode: Digital signature of the executable file has failed the verification
T1574 dropper_dll: Creates DLL, which is then loaded into the process

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
pe_overlay: PE file contains overlay
message_box: Displays a message