Managed XDR

vtdl_c_ypxh7r — malware analysis report

File info

Filename
vtdl_c_ypxh7r
File type
RFC 822 mail, ASCII text, with CRLF line terminators
File size
12.7 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
567a523789138578f52d40360553eebe7afc8dca
SHA256
3c41b4eb0712ced3c92b0b7a16c91ecac3d732a8d762532f760cd26e9ed34de5
MD5
6b4a61f58b07696489b975140223e73f

Signatures

Persistence

T1574 dropper_dll: Creates DLL, which is then loaded into the process

Privilege Escalation

T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1480 system_default_lang_id_present: Checks the system language
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1082 fingerprint_to_file: Collects data about system and user and writes it to a text file

Command and Control

T1102.003 references_google: Contains links to cloud services of Google (potentially for malicious payload delivery)

Other

yara_rules: Static rules
process_crashed: One of the processes has failed
no_graphical_activity: No graphic activity
valid_authenticode: The digital signature has been verified
has_pdb: This executable file has a PDB path
origin_langid: Unconventional language of the executable file
creates_in_programdata: Creates files in the ProgramData directory
test_check_service: Starts services
pe_overlay: PE file contains overlay