Managed XDR

vtdl_37_2s8iv — malware analysis report

File info

Filename
vtdl_37_2s8iv
File type
SMTP mail, ASCII text
File size
41.8 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
b40e39bb234183b2bc3cb8d1d4ac0dc5a4fa4307
SHA256
8ab408dc7e0dfdeb50b81c0c965962d3de6d210538d8c338565937324a6c16c0
MD5
002b2367624ad8d8aab1e9e1e78e7f92

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Other

yara_rules: Static rules
opens_document: Opens office documents
creates_doc: Creates (office) documents in the file system
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services