Managed XDR

vtdl_qn8xer53 — malware analysis report

File info

Filename
vtdl_qn8xer53
File type
PE32 executable (GUI) Intel 80386, for MS Windows
File size
328 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
a2754ff4e44a266092ee543ab30e33bc2fb6e455
SHA256
d209ca26c8140dd0bcd0ee730cd79ae69f3209c34b6fbc99e379fee0d32f688c
MD5
215475f901414ede8afa1c2615aeff4b

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
static_pe_anomaly: The PE file structure contains anomalies
non_quadratic_icon: Icon is not square
unexpected_exception: Unexpected exception
no_graphical_activity: No graphic activity
has_pdb: This executable file has a PDB path
origin_langid: Unconventional language of the executable file