Managed XDR

vtdl_lw_3ewln (BlackMatter, Lockbit) — malware analysis report

File info

Filename
vtdl_lw_3ewln
File type
PE32+ executable (GUI) x86-64, for MS Windows
File size
1.5 MB
First seen
Last seen

Environment

win7/x64 en

Hashes

SHA1
de684f1973d5c347758515b1b1db09d841177171
SHA256
081258ce17f6cc73f510d43d8d730735294b9754afd3c3c56de4ec5c1bb7c53c
MD5
e3119763a16b4f7a363d5a33ced2c7ec

Malwares

  • BlackMatter
  • Lockbit

Signatures

Execution

T1204.002 mimics_extension: Attempts to mimic the file extension

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1036 mimics_extension: Attempts to mimic the file extension
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
only_exec_in_archive: The archive contains only an executable file
no_graphical_activity: No graphic activity
has_pdb: This executable file has a PDB path
pe_overlay: PE file contains overlay

Related reports