Managed XDR

vtdl_rgz6cbzz — malware analysis report

File info

Filename
vtdl_rgz6cbzz
File type
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has command line arguments, Icon number=17, Normal, ctime=Wed Apr 11 23:34:00 2018, mtime=Tue Dec 13 11:13:12 2022, atime=Wed Apr 11 23:34:00 2018, length=13312, window=hide
File size
1.8 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
23255f9bafa4acb3b9b416ed1165486c226df955
SHA256
d1c0dc8ac428396ab49e16751d2f416215b63c85f13164f6c310f02a37eb88e2
MD5
008e8715cdaf700c26ef8ff0e86b641a

Signatures

Execution

T1204 suspicious_lnk: LNK file with suspicious content
T1059.003 suspicious_process: Spawns a suspicious process
T1059.001 url_cmdline: Cmdline of process contains URL
T1059.003 url_cmdline: Cmdline of process contains URL

Defense Evasion

T1218 suspicious_cmdline: Executes a suspicious command

Credential Access

T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files

Command and Control

T1071.001 network_http: Performs HTTP requests
T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp
T1071.001 wininet_https: Performs HTTP/HTTPS requests using WinInet

Other

yara_rules: Static rules
modifies_certs: Attempts to generate or modify system certificates
suspicious_process_network: Unusual process network activity detected
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
test_check_service: Starts services
suricata_alert: Malicious traffic detected