Managed XDR

vtdl_3uydsexs — malware analysis report

File info

Filename
vtdl_3uydsexs
File type
PE32 executable (GUI) Intel 80386, for MS Windows
File size
303.6 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
4f1b2f9a5bfa343da18762835b09a68b3a1423a9
SHA256
cbf16bbe0577fbe9f971bdc2d3efebbc2e6544e61f4e591e6e8a5ba46e585cc8
MD5
69f50e0f1729a47cca1d189aea3baf70

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1057 process_interest: Enumerates processes

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
origin_langid: Unconventional language of the executable file
pe_overlay: PE file contains overlay