Managed XDR

vtdl_q3ve3m_z — malware analysis report

File info

Filename
vtdl_q3ve3m_z
File type
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 1200, Locale ID: 2052, Author: XIAO, Template: Normal, Last Saved By: XIAO, Revision Number: 1, Create Time/Date: Wed Oct 29 12:08:00 2014, Last Saved Time/Date: Mon Nov 16 07:52:50 2015, Number of Pages: 1, Number of Words: 0, Number of Characters: 0, Name of Creating Application: WPS Of, Security: 0
File size
2.2 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
da2de3af99e8a49898a6a62e82e9cea0e4bf8f9c
SHA256
d922300cbb6f8f5c00b9475738c81a21c482b72e97b04a163ea5d8d0e2182a41
MD5
e49f0b922ea39c60a0125b45a5c3ab09

Signatures

Execution

T1106 susp_callbacks: Suspicious usage of some WinAPI with callbacks

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1497.001 antivm_queries_computername: Retrieves the computer name
T1497.002 async_mouse: Watches for mouse clicks using GetAsyncKeyState to detect human activity
T1497.002 antivm_usbstor: Reads information about usbdevices from regkey
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antivm_queries_computername: Retrieves the computer name
T1497.002 async_mouse: Watches for mouse clicks using GetAsyncKeyState to detect human activity
T1497.002 antivm_usbstor: Reads information about usbdevices from regkey
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1135 server_share_info: Retrieves information about each shared resource on a server

Other

yara_rules: Static rules
office_embedded: Office document contains embedded executable file(s)
static_pe_duplicate_sections: The PE file structure contains anomalies: duplicate section names
office_summary: The document contains suspicious metadata
create_rpc_bindings: Creates RPC connection
pdf_compressed_stream: Contains an object with compressed stream
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
office_links: Office file contains external links
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card