Managed XDR

vtdl_9avpf2qo — malware analysis report

File info

Filename
vtdl_9avpf2qo
File type
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
File size
1.4 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
1df58231ebe95a8eef1342b4765991f0ab443f41
SHA256
cd0bbdddcbb09a700de5e6003a6df9f17ef1a0aeb07f99e07d73977ef170d627
MD5
fd858fa8f250db2b5254cb23638d9eb9

Signatures

Persistence

T1574 dropper_dll: Creates DLL, which is then loaded into the process

Privilege Escalation

T1574 dropper_dll: Creates DLL, which is then loaded into the process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1574 dropper_dll: Creates DLL, which is then loaded into the process

Other

yara_rules: Static rules
static_pe_duplicate_sections: The PE file structure contains anomalies: duplicate section names
message_box: Displays a message