Managed XDR

vtdl_902wsa45 — malware analysis report

File info

Filename
vtdl_902wsa45
File type
Rich Text Format data, version 1, ANSI
File size
225.9 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
d76b77bce3eb06348cc78a0dddb7efa0729a89ee
SHA256
d4024a03c3860be98149fccabf7aec44bad8f38a53095bf3fe890181dd7a3683
MD5
c8d46542cdf9bd13d50e8ba99c5cb452

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1083 checks_recent_files: Attempt to check recently opened files through registry

Other

yara_rules: Static rules
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card