Managed XDR

vtdl_qkvl9_jw — malware analysis report

File info

Filename
vtdl_qkvl9_jw
File type
SMTP mail, ASCII text, with CRLF line terminators
File size
145.6 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
5e20817a95a5d965afbcc25d086d84955cecb89d
SHA256
899a3a08fa61368bae8eccc9ee8bee7eabf9147f19ef0ec116cfd057ee935b90
MD5
d55adb442707e2105becb448d427d564

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Command and Control

T1071.001 network_http: Performs HTTP requests

Other

yara_rules: Static rules
creates_exe: Creates executable files in the file system
create_process_failed: Could not start the process
creates_in_programdata: Creates files in the ProgramData directory
suricata_alert: Malicious traffic detected