Managed XDR

vtdl_gw9j3162 — malware analysis report

File info

Filename
vtdl_gw9j3162
File type
MS Windows shortcut, Item id list present, ctime=Fri Jul 19 10:19:47 2024, mtime=Fri Jul 19 10:19:47 2024, atime=Fri Jul 19 10:19:47 2024, length=0, window=hide
File size
1.1 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
6a6b7c2ae8e8a8d384d6a9b1a47bc63a5997cf7d
SHA256
0532aa0fff9bf360061f06d95185b2913f582416bffb0fb51576cf1d58645c82
MD5
0cd4595ea83c9502582976e711963f1a

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
no_graphical_activity: No graphic activity
creates_suspended_process: Creates suspended process