Managed XDR

vtdl_o2sqbdy0 — malware analysis report

File info

Filename
vtdl_o2sqbdy0
File type
PE32 executable (GUI) Intel 80386, for MS Windows
File size
444.5 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
cd56d11cccdc8833acd1aab9cb4f49e08bda1bf0
SHA256
c21c781b1d6bef06c81026fc0aab218ff772c6fbc5003cc0697f00513e80fcbe
MD5
af12aab4843379472859d442142b74c3

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
origin_langid: Unconventional language of the executable file