Managed XDR

vtdl_8c109u_d — malware analysis report

File info

Filename
vtdl_8c109u_d
File type
RFC 822 mail, ASCII text, with CRLF line terminators
File size
2.6 MB
First seen
Last seen

Environment

win7/x64 en

Hashes

SHA1
347bee43e23308aa04323bf75d2176fa0f3d7bbb
SHA256
3a4a3491d2d00c66153c633d6367d75243538ba57e310ac9545351117ee05a07
MD5
03ed4f63215f565eb003317311ec88e0

Signatures

Execution

T1059.001 suspicious_powershell: Creates suspicious powershell process

Privilege Escalation

T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1036 copies_utilities: Copies and runs system utility with different name
T1564.001 stealth_file: Creates hidden or system files
T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antivm_queries_computername: Retrieves the computer name

Other

executes_dropped_exe: Executes dropped exe files