Managed XDR

vtdl__ybhg4iu — malware analysis report

File info

Filename
vtdl__ybhg4iu
File type
RAR archive data, v5
File size
172 KB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
4aa178c7cb1f9b577969a8f992c859f87c7fb0e4
SHA256
dcbc803097ba3df09d74b36ec2c9f62f0a4161613bb71a0cc9b9315daec5775c
MD5
ac64c6b2079770ed0f8c3ec2d7d4cdba

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
has_pdb: This executable file has a PDB path
message_box: Displays a message
test_check_service: Starts services
many_files_in_archive: The archive contains more than 5 files