Managed XDR

vtdl_o3pyghal — malware analysis report

File info

Filename
vtdl_o3pyghal
File type
Composite Document File V2 Document, Cannot read section info
File size
3 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
59f1376dc00866b10115e9610dd958a9dbac8d02
SHA256
99c7101ef29e2f7e058ccfa85c6529292f967d05d3cd12ac71d03df4b44be2c6
MD5
5c14ba6c68372592b6288de45dc722f0

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
message_box: Displays a message
error_drawtext: An error occured while executing the file
checktokenmembership: Checks user token with CheckTokenMembership call