Managed XDR

vtdl_joz2hk04 — malware analysis report

File info

Filename
vtdl_joz2hk04
File type
PE32 executable (DLL) (console) Intel 80386, for MS Windows
File size
377.5 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
aa56f43e39d114235a6b1d5f66b593cc80325fa4
SHA256
97bae3587f1d2fd35f24eb214b9dd6eed95744bed62468d998c7ef55ff8726d4
MD5
acac995cee8a6a75fa79eb41bdffa53f

Signatures

Execution

T1559 no_graphical_activity: No graphic activity
T1559 message_box: Displays a message

Persistence

T1574 dropper_dll: Creates DLL, which is then loaded into the process

Privilege Escalation

T1574 dropper_dll: Creates DLL, which is then loaded into the process

Defense Evasion

T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1027.002 packer_entropy: Probably contains compressed or encrypted data

Discovery

T1518 locates_browser: Attempts to identify where browsers are installed

Other

yara_rules: Static rules
pe_overlay: PE file contains overlay