Managed XDR

vtdl_9mg8zed5 — malware analysis report

File info

Filename
vtdl_9mg8zed5
File type
MS Windows shortcut, Item id list present, ctime=Fri Nov 13 05:40:15 2009, mtime=Fri Nov 13 05:40:15 2009, atime=Fri Nov 13 05:40:15 2009, length=0, window=hide
File size
1.1 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
32f3043133548603fcb2197a6d6c9f2c325b1e8f
SHA256
2ed923525298adf8af421f2c8d261ef572b154c4779da2a6eb5b68c701b20bf2
MD5
511f971b012130e8390a9a4a49ecc3a2

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process