Managed XDR

vtdl_fg181_io — malware analysis report

File info

Filename
vtdl_fg181_io
File type
RFC 822 mail, ASCII text, with CRLF line terminators
File size
3.2 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
0324fe1e490feead436606f91a7f841de79c2345
SHA256
e4783027ad2aec21892708c96fde2bfe33e14393839ca636cdce4548dc8cf361
MD5
835f196dbfe29d1ea30a3003647cf54a

Signatures

Privilege Escalation

T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1070 stealth_window: A process created a hidden window
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
create_process_failed: Could not start the process
no_graphical_activity: No graphic activity
creates_suspended_process: Creates suspended process
dotnet_import_unmanaged_code: Dotnet program statically imports unmanaged functions/modules
get_policy_info: Retrieves information about a Policy object
checktokenmembership: Checks user token with CheckTokenMembership call