Managed XDR

vtdl_je4gfe2d — malware analysis report

File info

Filename
vtdl_je4gfe2d
File type
RAR archive data, v5
File size
840.7 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
a7e3b0469aa9ea5fcc529b32cb2a4e6883ed3df7
SHA256
a0cec7362adb7b533559aa8103369123ea5ad156f0df940cc5dc65dba521bdfb
MD5
7d441089a119819e6ddf13836adf7924

Signatures

Persistence

T1574 dropper_dll: Creates DLL, which is then loaded into the process

Privilege Escalation

T1574 dropper_dll: Creates DLL, which is then loaded into the process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1574 dropper_dll: Creates DLL, which is then loaded into the process

Discovery

T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Other

yara_rules: Static rules
creates_exe: Creates executable files in the file system
only_exec_in_archive: The archive contains only an executable file
create_rpc_bindings: Creates RPC connection
require_administrator: Requests administrator privileges
get_memory_status: Gets information about the virtual and physical memory of the system