Managed XDR

vtdl_poyk_mnw — malware analysis report

File info

Filename
vtdl_poyk_mnw
File type
RFC 822 mail, ASCII text, with CRLF line terminators
File size
118.8 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
027cdda568918670d7106d88157ce015bbd5ae49
SHA256
09158a8d8cc8796ad40951390963dcf3b0e2a84a3d7e4b7492f695a2f5ffc35d
MD5
e4d6e614eb66cd6a577e3525b9cb0273

Signatures

Command and Control

T1102.003 references_azure: Contains links to cloud services of Azure (potentially for malicious payload delivery)

Other

yara_rules: Static rules
suspicious_pdf: PDF file with suspicious content
pdf_page: Contains only one page
create_rpc_bindings: Creates RPC connection
pdf_compressed_stream: Contains an object with compressed stream
get_sid_domain: Get user's SID
office_links: Office file contains external links
get_memory_status: Gets information about the virtual and physical memory of the system