Managed XDR

vtdl_1744358657_n0ae6ko_ — malware analysis report

File info

Filename
vtdl_1744358657_n0ae6ko_
File type
PE32 executable (console) Intel 80386, for MS Windows
File size
355.5 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
c6743c87ed4c6275891362566e9e26c0a7f999fc
SHA256
469140919090af802c44ce8a4a622e3a25bb3fba9c28f86e55eff46f7c4b7675
MD5
ba419fcc5ec5d98b241ae30ee4473002

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1057 process_interest: Enumerates processes

Other

yara_rules: Static rules
creates_in_windows: Creates files in the Windows directory
creates_exe: Creates executable files in the file system
require_administrator: Requests administrator privileges
has_pdb: This executable file has a PDB path
break_limit_exceeded: Warning: function calls limit has been exceeded
origin_langid: Unconventional language of the executable file