Managed XDR

vtdl_1742197583_j0hksrw2 (Grimagent) — malware analysis report

File info

Filename
vtdl_1742197583_j0hksrw2
File type
PE32 executable (GUI) Intel 80386, for MS Windows
File size
268 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
c87d76e59e3f4d0233e98f8574eec20d2984d57e
SHA256
66e5796377a38f3dfa8cb03d6ecb74a3e374e9f5535f9951322114f6bd80a0a3
MD5
0ce719ac20f419b5646feca1df5c936b

Malwares

  • Grimagent

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity

Related reports