Managed XDR

vtdl_k_3o1_oe — malware analysis report

File info

Filename
vtdl_k_3o1_oe
File type
CDFV2 Encrypted
File size
144.1 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
c60071af876de49b6502fc8c5ed0bb3f8cb4c007
SHA256
3303c27b8efa5e738b8c5f68360b33539ad58a1606c30c94a50885199ea8e921
MD5
9aa48f4cb99e033184c85fd026270b52

Signatures

Defense Evasion

T1497 windows_enumthread: Attempts to enumerate windows using EnumThreadWindows and SendMessage for text obtaining

Discovery

T1497 windows_enumthread: Attempts to enumerate windows using EnumThreadWindows and SendMessage for text obtaining
T1082 windows_enumthread: Attempts to enumerate windows using EnumThreadWindows and SendMessage for text obtaining

Other

yara_rules: Static rules
get_memory_status: Gets information about the virtual and physical memory of the system
get_sid_domain: Get user's SID
get_username: Gets username
test_check_service: Starts services
create_rpc_bindings: Creates RPC connection