Managed XDR

vtdl_1735019823__2c71ras — malware analysis report

File info

Filename
vtdl_1735019823__2c71ras
File type
MS Windows shortcut, Item id list present, Has Working directory, Has command line arguments, Icon number=339, ctime=Tue Jul 30 13:14:34 2024, mtime=Tue Jul 30 13:14:34 2024, atime=Tue Jul 30 13:14:34 2024, length=0, window=hidenormalshowminimized
File size
789 Bytes
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
54a4241578fd30efcff6734336fd5005ddae2153
SHA256
96dccf3f6b5288a5f5a6d6534b3bf9188aaaa85eb637510a972cf992063e66f7
MD5
3962e1d8373a62493a7f3245ef357570

Signatures

Execution

T1204 suspicious_lnk: LNK file with suspicious content

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.001 antivm_disk_size: Checks the amount of free disk space
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antivm_disk_size: Checks the amount of free disk space

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process