Managed XDR

vtdl_rz7abzcf — malware analysis report

File info

Filename
vtdl_rz7abzcf
File type
Zip archive data, at least v2.0 to extract
File size
710.3 KB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
7c4f426fd096375520d5eac8359f2ba90c2ef36d
SHA256
b1e259f1698b87c864a6b09c9365aaaf082cafe3970b1cc8f2002b4a7d67d69c
MD5
fd7708a7a47357cc877787a9a7a6d9d4

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.001 antivm_vbox_devices: Detects VirtualBox through the presence of a device
T1497.001 antivm_vmware_devices: Detects VMware through the presence of a certain device
T1497.001 antivm_vbox_files: Detects VirtualBox through the presence of a file
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antivm_vbox_devices: Detects VirtualBox through the presence of a device
T1497.001 antivm_vmware_devices: Detects VMware through the presence of a certain device
T1497.001 antivm_vbox_files: Detects VirtualBox through the presence of a file

Other

yara_rules: Static rules
only_exec_in_archive: The archive contains only an executable file
no_graphical_activity: No graphic activity
require_administrator: Requests administrator privileges
test_check_service: Starts services
pe_overlay: PE file contains overlay