Managed XDR

vtdl_1736488813_9e0v_3sn — malware analysis report

File info

Filename
vtdl_1736488813_9e0v_3sn
File type
PE32 executable (GUI) Intel 80386, for MS Windows
File size
553 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
7c444462989d8452dc4530e2688bbbaf04948d42
SHA256
125488eb6c206b9ffd1f9da07c02255cef9c60e1c03865e38a6e75e3f3ffea20
MD5
7d6976f87811c53ba9b9915ad11fc49b

Signatures

Persistence

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup

Privilege Escalation

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
creates_exe: Creates executable files in the file system
copies_self: Creates a copy of itself
dead_host: Connects to IP addresses that do not respond to requests
no_graphical_activity: No graphic activity