Managed XDR

vtdl_1748917963_cygjq0iy — malware analysis report

File info

Filename
vtdl_1748917963_cygjq0iy
File type
MS Windows shortcut, Item id list present, Points to a file or directory, Has command line arguments, Icon number=7, Archive, ctime=Mon Jul 21 09:03:56 2008, mtime=Tue May 22 07:41:45 2018, atime=Mon Apr 14 12:00:00 2008, length=398336, window=hidenormalshowminimized
File size
1.6 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
18a585f15cda8b9b0acd63d0faf6126e70738012
SHA256
5d9620e444fabd3271d837667a3396d142a521ccc11f047c45000043db71d212
MD5
620eac937cff2e303370a406b8ea6197

Signatures

Execution

T1204 suspicious_lnk: LNK file with suspicious content

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object