Managed XDR

vtdl_xi8taciz — malware analysis report

File info

Filename
vtdl_xi8taciz
File type
RAR archive data, v5
File size
13.4 MB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
a62c31b15a4290538b0653c27222a1224b8483c3
SHA256
b4363dd81097159c3a42f40ad71fd176f5a1b3c213ec41dbd8932b4fd7ecbd69
MD5
bdb44acb3858100e51fcf7dcef309b9c

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
require_administrator: Requests administrator privileges
creates_suspended_process: Creates suspended process
message_box: Displays a message