Managed XDR

vtdl_wesikbtr — malware analysis report

File info

Filename
vtdl_wesikbtr
File type
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Mon Mar 18 08:17:01 2024, mtime=Mon Mar 18 08:17:01 2024, atime=Mon Mar 18 08:17:01 2024, length=1254776, window=hide
File size
932 Bytes
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
d1e22094638dd9d9415569b352ff89ad58cbe3fd
SHA256
646127bc6f407fff97803b9c394543e0653cdd2dc76e91b7f702979f407819a4
MD5
eec7e6ff6a6f3a54b0a4032a3cdcf693

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object