Managed XDR

vtdl_n9rldczv — malware analysis report

File info

Filename
vtdl_n9rldczv
File type
MS Windows shortcut, Item id list present, Points to a file or directory, Has command line arguments, Icon number=7, Archive, ctime=Sun Mar 29 18:28:36 2015, mtime=Sun Mar 29 18:28:36 2015, atime=Sat Nov 20 13:24:33 2010, length=345088, window=hidenormalshowminimized
File size
1.6 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
766713919e1654ad866510f4c3d57f8d91cf1225
SHA256
68666cd5afa10de53ae8f93885a6d9d17c2de6a9d67aaad4a2c8245823a15b9c
MD5
bdab9567392f15c0d8a066d60282140a

Signatures

Execution

T1204 suspicious_lnk: LNK file with suspicious content

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
no_graphical_activity: No graphic activity
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object