Managed XDR

vtdl_mudzpab0 — malware analysis report

File info

Filename
vtdl_mudzpab0
File type
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
File size
1.6 MB
First seen
Last seen

Environment

win7/x64 en

Hashes

SHA1
042969a52426dc9b9f0d50366ab78d6f9e13ab2d
SHA256
48f3ead8477f3ef16da6b74dadc89661a231c82b96f3574c6b7ceb9c03468291
MD5
72d42863592d74c68fd2b9ece1bde6cf

Signatures

Persistence

T1574 dropper_dll: Creates DLL, which is then loaded into the process

Privilege Escalation

T1574 dropper_dll: Creates DLL, which is then loaded into the process

Defense Evasion

T1574 dropper_dll: Creates DLL, which is then loaded into the process

Other

yara_rules: Static rules
process_crashed: One of the processes has failed
message_box: Displays a message
test_check_service: Starts services