Managed XDR

vtdl_xtqngr9f (Neshta) — malware analysis report

File info

Filename
vtdl_xtqngr9f
File type
PE32 executable (GUI) Intel 80386, for MS Windows, RAR self-extracting archive
File size
823 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
4a4b52c2ae4fcecad5afdcc670b1749f87ba8166
SHA256
c5c17d6bb35d580022eb67209223bf2b1e1be16616e6900a04376f85393ad1c8
MD5
69f27597f8b50cb6bcf3b48743162f89

Malwares

  • Neshta

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
process_crashed: One of the processes has failed
no_graphical_activity: No graphic activity
require_administrator: Requests administrator privileges
has_pdb: This executable file has a PDB path
origin_langid: Unconventional language of the executable file
test_check_service: Starts services
pe_overlay: PE file contains overlay

Related reports