Managed XDR

vtdl_p5e_c3zq — malware analysis report

File info

Filename
vtdl_p5e_c3zq
File type
RAR archive data, v4, os: Win32
File size
12.2 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
4e5565bfb1b754e4e8d6fcf05c9cdcd52c1beff0
SHA256
8d3b7517f42050f914b5592d1697a65b400ecd96e7fec02322b8e38f3b3bb985
MD5
4d337df43d0b3559275b118658d05327

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_themida: Themida packer signatures detected
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1480 system_default_lang_id_present: Checks the system language
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files

Other

yara_rules: Static rules
static_pe_anomaly: The PE file structure contains anomalies
process_crashed: One of the processes has failed
unexpected_exception: Unexpected exception
no_graphical_activity: No graphic activity
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
checktokenmembership: Checks user token with CheckTokenMembership call
pe_overlay: PE file contains overlay