Managed XDR

vtdl_7o8n1cuy — malware analysis report

File info

Filename
vtdl_7o8n1cuy
File type
RAR archive data, v5
File size
4.6 MB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
880f6bfb7eb5f57b3417b64415a43948eef01dd7
SHA256
247a4b400a077b494de8208842ead96409377d6b453c214c6527a07f5af653d4
MD5
71c9c7c23fa3350022c99f66e1d0a16f

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
require_administrator: Requests administrator privileges
has_pdb: This executable file has a PDB path
creates_suspended_process: Creates suspended process
test_check_service: Starts services