Managed XDR

vtdl_f_owxnhk (Tinba) — malware analysis report

File info

Filename
vtdl_f_owxnhk
File type
RAR archive data, v5
File size
3.9 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
04c7f12533cd9ecf36fca8b33704766c7213a193
SHA256
af68ae7326af74a8747e30d30594c5ef50e8db8ad592160037f7e40a3761c7ae
MD5
9d51e239ec2d638814d21990c75874f3

Malwares

  • Tinba

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_vmprotect: Executable file is likely compressed using VMProtect
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
static_pe_anomaly: The PE file structure contains anomalies
no_graphical_activity: No graphic activity
require_administrator: Requests administrator privileges
has_pdb: This executable file has a PDB path
origin_langid: Unconventional language of the executable file

Related reports