Managed XDR

vtdl_3it0hbnt — malware analysis report

File info

Filename
vtdl_3it0hbnt
File type
Zip archive data, at least v1.0 to extract
File size
8.1 MB
First seen
Last seen

Environment

w10/x86 en

Hashes

SHA1
dfc5592ad65525e5996efc8bc0b07ff25b3b5cab
SHA256
7ab149192940b747c6fbf05b7b6214d45411d22919ec6c0f0f0c47a911afefef
MD5
f7acc46f25ea17f55b25cf3566865ad5

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1036 system_filename: Created a file named as a common system file
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
creates_exe: Creates executable files in the file system
create_process_failed: Could not start the process
executes_dropped_exe: Executes dropped exe files
only_exec_in_archive: The archive contains only an executable file
dotnet_suspicious_resources_names: Dotnet program has suspicious resources names
creates_suspended_process: Creates suspended process
suspicious_network_port: Performs TCP or UDP request to non-standard port
test_check_service: Starts services