Managed XDR

vtdl_cdl6rioo — malware analysis report

File info

Filename
vtdl_cdl6rioo
File type
Microsoft Word 2007+
File size
19.7 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
add8acf927b2f6b06bb6a2aa67392315aa78e749
SHA256
151143770a16cef52f47875f2a0404c3344813beeb6476e92a7c6476bc2a6cc0
MD5
13a8e7a2382949df69f66ef5fa6b9d7f

Signatures

Execution

T1204.002 office_vb_load: Microsoft Office is loading VB DLL files (macros usage indicator)

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antivm_queries_computername: Retrieves the computer name
T1083 checks_recent_files: Attempt to check recently opened files through registry

Other

yara_rules: Static rules
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card