Managed XDR

vtdl_1vqpq5rp — malware analysis report

File info

Filename
vtdl_1vqpq5rp
File type
MS Windows shortcut, Item id list present, Has command line arguments, Icon number=28, ctime=Mon Jan 1 00:00:00 1601, mtime=Mon Jan 1 00:00:00 1601, atime=Mon Jan 1 00:00:00 1601, length=0, window=hidenormalshowminimized
File size
2 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
10c5fce5875ff9a5192207fef8c9da5cfc902b00
SHA256
ed86416a42dfebe4cbbb7c0e493a68e9bffed642bc397e4591667c9f4b9cff48
MD5
7e3b979965414733c60182d2b355ff6b

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1518 locates_browser: Attempts to identify where browsers are installed

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object