Managed XDR

vtdl_ahww30wu — malware analysis report

File info

Filename
vtdl_ahww30wu
File type
PE32 executable (GUI) Intel 80386, for MS Windows
File size
1.9 MB
First seen
Last seen

Environment

w10/x86 en

Hashes

SHA1
9edac84a8458c743df2d81be9e01536342477181
SHA256
779a45fdb0d9508d6f1934201c17514bf4c1b4a056f3cd776fc2591704c83dcc
MD5
069c9d1542966b58a51ea7e4927461ce

Signatures

Privilege Escalation

T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1057 pidbruteforce: Enumerates processes using PID Bruteforce
T1135 server_share_info: Retrieves information about each shared resource on a server

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
create_rpc_bindings: Creates RPC connection
access_recyclebin: Manipulation with recyclebin detected
test_check_service: Starts services
checktokenmembership: Checks user token with CheckTokenMembership call