Managed XDR

vtdl_aldwy30m — malware analysis report

File info

Filename
vtdl_aldwy30m
File type
SMTP mail, ISO-8859 text
File size
7.2 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
53c2f0e92a74558f2a458be2e21f4a5d4bd5982a
SHA256
3ef380eddbec4356726e8559deb634a46d1f23227f6e685f8051e483741f2f68
MD5
dc98966202f1ed44504b4ff792eb3bb2

Signatures

Execution

T1204.002 mimics_extension: Attempts to mimic the file extension

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1036 mimics_extension: Attempts to mimic the file extension
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
process_crashed: One of the processes has failed
no_graphical_activity: No graphic activity