Managed XDR

vicidial_webrtc_driver_1.0.exe — malware analysis report

File info

Filename
vicidial_webrtc_driver_1.0.exe
File type
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
File size
28.3 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
7a00a24a324593a86e4e87c7fbc31dab40722b68
SHA256
fa3ea8354a6546dfd20ab463ee16f6b98fbc3833de9f94bbe98f5c96dfebe902
MD5
a1eadfca4fa3ba1dcd7a67aa06e413bf

Signatures

Persistence

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup

Privilege Escalation

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1518 locates_browser: Attempts to identify where browsers are installed

Other

create_process_failed: Could not start the process
no_graphical_activity: No graphic activity
creates_exe: Creates executable files in the file system