Managed XDR

vtdl_bsxb9b63 — malware analysis report

File info

Filename
vtdl_bsxb9b63
File type
PE32 executable (GUI) Intel 80386, for MS Windows
File size
9.7 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
95562f80f1b334690c056e21c015c8b122d07d27
SHA256
d62420c095febc15f399e7e391c36500760503f0d5f06ee3810f84e995b3a930
MD5
56b8f9d9c6c5748740719a2e31e15a5a

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
has_pdb: This executable file has a PDB path