Managed XDR

vtdl__5y75v4t — malware analysis report

File info

Filename
vtdl__5y75v4t
File type
RAR archive data, v5
File size
424.1 KB
First seen
Last seen

Environment

win7/x64 en

Hashes

SHA1
c5b0031c312fba26e63e30c48fc8559d3344b50d
SHA256
b5785e589c750f0156f6c24e246b18419d3b8c49e680e517802e24dd7928b4c8
MD5
2e257fd59b98f74a31085600323918db

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1070 stealth_window: A process created a hidden window
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
creates_exe: Creates executable files in the file system
executes_dropped_exe: Executes dropped exe files
require_administrator: Requests administrator privileges
message_box: Displays a message
get_policy_info: Retrieves information about a Policy object