Managed XDR

vtdl__459_45j — malware analysis report

File info

Filename
vtdl__459_45j
File type
SMTP mail, UTF-8 Unicode text
File size
101.9 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
7fc6658d8199c99e5690eddc03d730b4a1edbbfd
SHA256
532ed3352f8923f6a568ce4c26493febae87c30ecc39609b4a8204e335aab2e5
MD5
c426c256d1d2032a331ba9ebb2a91388

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
get_policy_info: Retrieves information about a Policy object
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card