Managed XDR

vtdl_3b8h8rkg — malware analysis report

File info

Filename
vtdl_3b8h8rkg
File type
MS Windows shortcut, Item id list present, Points to a file or directory, Has command line arguments, Icon number=7, Archive, ctime=Sun Dec 17 09:31:16 2023, mtime=Sun Dec 31 08:24:40 2023, atime=Sun Dec 17 09:31:16 2023, length=289792, window=hidenormalshowminimized
File size
1.7 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
202064e946ca0bcef4eb6e1e4dc4fdbcb0fa18c2
SHA256
75f228cde873a8dcb1ba896a969eed5ca849addc47cccf46288bfb390f74a05b
MD5
60ab339429e92e01a7c205823ec6805a

Signatures

Execution

T1204 suspicious_lnk: LNK file with suspicious content

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object