Managed XDR

vtdl_em_9hdt2 — malware analysis report

File info

Filename
vtdl_em_9hdt2
File type
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 1251, Author: , Template: Normal, Last Saved By: , Revision Number: 10, Name of Creating Application: Microsoft Office Word, Total Editing Time: 10:18:00, Last Printed: Mon Jan 16 08:14:00 2017, Create Time/Date: Tue Mar 28 13:04:00 2017, Last Saved Time/Date: Wed Jul 19 14:26:00 2017, Number of Pages: 1, Number of Words: 256, Number of Characters: 1464, Security: 0
File size
89 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
9235e0f59caddb7c4af8944b8b8885ed0ed89791
SHA256
366661573523eefd646b4a65157d390b8036be495b70766fa514b758b1ead021
MD5
87718f5f8f8efae9a6b45d9a535b7a01

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files

Discovery

T1497.001 antivm_queries_computername: Retrieves the computer name
T1135 server_share_info: Retrieves information about each shared resource on a server

Other

yara_rules: Static rules
create_rpc_bindings: Creates RPC connection
get_policy_info: Retrieves information about a Policy object
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card