Managed XDR

vtdl_o17n8k01 — malware analysis report

File info

Filename
vtdl_o17n8k01
File type
Zip archive data, at least v2.0 to extract
File size
10.2 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
7c99739aa859578632928f206d8980fb88775fd8
SHA256
8a2140c547bca8b193372ae7e651a927afa774ec2082f08a923680a14b9637d3
MD5
e0eac0e9f0ea7ec27f75d508f53d45c4

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
creates_exe: Creates executable files in the file system
no_graphical_activity: No graphic activity
require_administrator: Requests administrator privileges
message_box: Displays a message