Managed XDR

vtdl_abqednhe (RMS) — malware analysis report

File info

Filename
vtdl_abqednhe
File type
PE32 executable (GUI) Intel 80386, for MS Windows
File size
12.6 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
d9b13986c271e5ad7116b9045d54a12bec176f11
SHA256
d191cf4174cb7a3b0445804fb8c0225766feacf3100c38b728b71b437e7c4688
MD5
19863dd0ba4c03f2663758c5a2f8ceca

Malwares

  • RMS

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.001 antisandbox_productid: Obtains Windows ProductID, probably to fingerprint a sandbox
T1036.001 invalid_authenticode: Digital signature of the executable file has failed the verification
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1497 antidbg_strings: Checks for malware analysis tools (specific strings found)
T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antisandbox_productid: Obtains Windows ProductID, probably to fingerprint a sandbox
T1497 antidbg_strings: Checks for malware analysis tools (specific strings found)
T1497.001 antivm_queries_computername: Retrieves the computer name

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
pe_overlay: PE file contains overlay
open_winlogon_process: Trying to open winlogon process

Related reports