Managed XDR

vtdl_hplpsyvr — malware analysis report

File info

Filename
vtdl_hplpsyvr
File type
Microsoft Word 2007+
File size
10.1 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
9a5b9ffd2a81c3617de26f38420e2a09ff50a79a
SHA256
f3f4103d56bdde893f4b8bae4237964e8dd816571769ff5a70b1cd7a93876bd8
MD5
7e8339891fd1d5c88c976f32b8eab516

Signatures

Execution

T1559 suricata_alert: Malicious traffic detected
T1559 creates_doc: Creates (office) documents in the file system
T1559 unexpected_exception: Unexpected exception
T1559 process_crashed: One of the processes has failed
T1559 get_sid_domain: Get user's SID
T1559 test_check_service: Starts services
T1559 create_rpc_bindings: Creates RPC connection

Privilege Escalation

T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges

Defense Evasion

T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges

Discovery

T1497.001 antivm_queries_computername: Retrieves the computer name
T1083 checks_recent_files: Attempt to check recently opened files through registry

Command and Control

T1071.001 network_http: Performs HTTP requests
T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp
T1071.001 wininet_https: Performs HTTP/HTTPS requests using WinInet

Other

yara_rules: Static rules
get_memory_status: Gets information about the virtual and physical memory of the system
get_username: Gets username