Managed XDR

vtdl_4c7nhfqt — malware analysis report

File info

Filename
vtdl_4c7nhfqt
File type
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Archive, ctime=Tue Jan 30 15:32:46 2024, mtime=Fri Feb 23 14:42:03 2024, atime=Tue Jan 30 15:32:46 2024, length=455680, window=hide
File size
2 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
58f929ff64d90330d7b4e737c7d1f5fe2d532fc1
SHA256
7496c06679c8fcee7fe99f119bb5965ed28d13a29664df0513c4b57390813a21
MD5
999fdd1302a5c87cf5ca5991d9516681

Signatures

Execution

T1204 suspicious_lnk: LNK file with suspicious content
T1059.001 suspicious_powershell: Creates suspicious powershell process
T1059.001 suspicious_process: Spawns a suspicious process
T1059.001 url_cmdline: Cmdline of process contains URL
T1059.003 url_cmdline: Cmdline of process contains URL

Other

yara_rules: Static rules
code_share_services: Connects to text storage services (potentially for malicious payload delivery)
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process