Managed XDR

vtdl_4elx8hdn — malware analysis report

File info

Filename
vtdl_4elx8hdn
File type
RAR archive data, v5
File size
173.7 KB
First seen
Last seen

Environment

w10/x86 en

Hashes

SHA1
c4795b3aadf001435420dd552fad14f598606ef5
SHA256
f0ad5c1ba945415b037e17965de290ca613edd1d7b0ba9917929b093b3a84279
MD5
ce04368a520a056a438df57ebd479aad

Signatures

Persistence

T1574 dropper_dll: Creates DLL, which is then loaded into the process

Privilege Escalation

T1055.012 injection_runpe: Injects code into another process
T1055 sets_debug_registers: Sets debug registers for a thread in a different process
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1055.012 injection_runpe: Injects code into another process
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1055 sets_debug_registers: Sets debug registers for a thread in a different process
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_process_token: Opens the access token associated with a process

Other

suspicious_process: Spawns a suspicious process
unexpected_exception: Unexpected exception
valid_authenticode: The digital signature has been verified
has_pdb: This executable file has a PDB path
creates_suspended_process: Creates suspended process
test_check_service: Starts services
pe_overlay: PE file contains overlay