Managed XDR

vtdl_etokwn0m — malware analysis report

File info

Filename
vtdl_etokwn0m
File type
Rich Text Format data, unknown version
File size
156 Bytes
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
bd874351c6b4b69e6215726f952ea2c9e3cd7a38
SHA256
7a3a63707727ee1cfc35ce6b2eec8a65ad79cf7fb247c8eb2ddf762920e504f1
MD5
38cb279556dd1924d0e9d9bb8c479be8

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antivm_queries_computername: Retrieves the computer name

Other

yara_rules: Static rules
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card