Managed XDR

vtdl_1ushjusz — malware analysis report

File info

Filename
vtdl_1ushjusz
File type
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
File size
124.5 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
7ec919cb8ea81f9b2c382e4fcb84a97796396bfe
SHA256
c848903b22087c4f037103ea3ea00cfbbb6f682bac60e0b2bff36a38242798c4
MD5
8e4735922d2603c1df0f3fae4271fdf4

Malwares

Signatures

Persistence

T1574 dropper_dll: Creates DLL, which is then loaded into the process

Privilege Escalation

T1574 dropper_dll: Creates DLL, which is then loaded into the process

Defense Evasion

T1574 dropper_dll: Creates DLL, which is then loaded into the process

Credential Access

T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files

Command and Control

T1071.001 network_cnc_http: Suspicious HTTP traffic
T1071.001 network_http: Performs HTTP requests
T1071.001 wininet_https: Performs HTTP/HTTPS requests using WinInet

Other

yara_rules: Static rules
suspicious_process_network: Unusual process network activity detected
no_graphical_activity: No graphic activity
creates_suspended_process: Creates suspended process
message_box: Displays a message