Managed XDR

vtdl_1738710407_ayb2d2ol — malware analysis report

File info

Filename
vtdl_1738710407_ayb2d2ol
File type
PE32 executable (console) Intel 80386, for MS Windows, UPX compressed
File size
252 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
be4a0c24ccab6dd0e8d2d22ea4480492c5ff252e
SHA256
14580417a18f7a6a51dffdbaa81d5f65dd4242d42008dfc4063a216520b7f9fd
MD5
82b8221d49674b02b8feee507fc9634a

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_upx: The executable file is compressed using UPX
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1552.002 opens_registry_hive_file: Attempts to open Windows registry hive file
T1003.002 opens_registry_hive_file: Attempts to open Windows registry hive file

Other

yara_rules: Static rules