Managed XDR

vtdl_d18q7qwb — malware analysis report

File info

Filename
vtdl_d18q7qwb
File type
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has command line arguments, Icon number=13, Archive, ctime=Wed Oct 6 13:51:36 2021, mtime=Fri Dec 15 04:18:39 2023, atime=Wed Oct 6 13:51:36 2021, length=289792, window=hidenormalshowminimized
File size
2.3 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
ae303ffdc11d1a04cceae5c4dbd9726609a41145
SHA256
23aa3b598c51c0815c9eece9dba8a47bc8ecbc8226d8e32941f946a3b5a15a31
MD5
d1799a40763709073f368b73c31bb295

Signatures

Execution

T1204 suspicious_lnk: LNK file with suspicious content
T1059.003 executes_dropped_cmd: Executes dropped batch files
T1203 suspicious_msapp: Suspicious execution of Microsoft Application (possible exploitation)

Other

suricata_alert: Malicious traffic detected
creates_exe: Creates executable files in the file system
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
yara_rules: Static rules