Managed XDR

vtdl_48b6_w24 — malware analysis report

File info

Filename
vtdl_48b6_w24
File type
RAR archive data, v5
File size
1.7 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
d54add7b7170b29fed756765ddf9ff1e8e124cb3
SHA256
035cc0eb50d06c22c51052588f937822b4f51112c1c6cf7403fc30759de152f6
MD5
c7144f4364c1853ceef893b0455e2bc5

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
creates_exe: Creates executable files in the file system
create_process_failed: Could not start the process
executes_dropped_exe: Executes dropped exe files
only_exec_in_archive: The archive contains only an executable file
require_administrator: Requests administrator privileges