Managed XDR

vtdl_1738392252_jkqln31y — malware analysis report

File info

Filename
vtdl_1738392252_jkqln31y
File type
PE32 executable (GUI) Intel 80386, for MS Windows
File size
531.5 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
6b2fcec8739cbe11f32cccebe91eb8efe7fc9f51
SHA256
b51b323e02abb7a956c3ff26329af23e5d2ec4c66fa9e4551506c7c1789c0280
MD5
70cfa0f4218a8db2d6ee41c7de239066

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1070.004 deletes_self: Moves to different location or removes the original executable file
T1027.002 packer_polymorphic: Creates a modified copy of itself
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1497.001 antivm_queries_computername: Retrieves the computer name
T1070 stealth_window: A process created a hidden window
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antivm_queries_computername: Retrieves the computer name

Other

yara_rules: Static rules
executes_dropped_exe: Executes dropped exe files
unexpected_exception: Unexpected exception
no_graphical_activity: No graphic activity