Managed XDR

vtdl_c_bmc59x — malware analysis report

File info

Filename
vtdl_c_bmc59x
File type
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Fri Jan 15 06:18:19 2021, mtime=Sat Oct 9 11:27:24 2021, atime=Fri Jan 15 06:18:19 2021, length=236544, window=hide
File size
2 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
e60d373c2dc3d7739fa14d3ed38827c66e35afdb
SHA256
b09ce2e0df23f7708a6192982a55f3ad4c3b5c433293f1825b060e0b406d5405
MD5
77fb433f957d21f1d8cdd3d03ae442f3

Signatures

Execution

T1204 suspicious_lnk: LNK file with suspicious content
T1059.001 url_cmdline: Cmdline of process contains URL
T1059.003 url_cmdline: Cmdline of process contains URL

Defense Evasion

T1218 suspicious_cmdline: Executes a suspicious command

Credential Access

T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files

Command and Control

T1071.001 network_http: Performs HTTP requests
T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp
T1071.001 wininet_https: Performs HTTP/HTTPS requests using WinInet

Other

unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
yara_rules: Static rules