Managed XDR

vtdl_vnpob3d_ — malware analysis report

File info

Filename
vtdl_vnpob3d_
File type
Non-ISO extended-ASCII text, with very long lines, with CRLF, CR, LF line terminators
File size
132 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
de9b3c6902882b22f14dab09f83c995952c44e26
SHA256
484f7e4feb702a830009048f67fd03706bab2953dd8163f8db0268b49b83c96f
MD5
201df4ed5e5626b05e5db42e9fe58d4c

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1083 checks_recent_files: Attempt to check recently opened files through registry
T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents

Other

yara_rules: Static rules
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card