Managed XDR

vtdl_esg_y7vm — malware analysis report

File info

Filename
vtdl_esg_y7vm
File type
PE32 executable (GUI) Intel 80386, for MS Windows
File size
411.5 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
12a5acbd7b8939090e443657cbc755e40d6f7903
SHA256
1420b45b7ca1b037bc1e4c2653065fa46069dc3c7d271557c7f6f26801323b32
MD5
3ce6c1f599dd930453ae0cfeffcef60d

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
origin_langid: Unconventional language of the executable file