Managed XDR

vtdl_21qmwcpe — malware analysis report

File info

Filename
vtdl_21qmwcpe
File type
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: -535, Author: , Template: Normal, Last Saved By: , Revision Number: 3, Name of Creating Application: Microsoft Office Word, Total Editing Time: 01:00:00, Last Printed: Mon Apr 1 09:26:00 2024, Create Time/Date: Mon Apr 1 09:05:00 2024, Last Saved Time/Date: Wed Apr 24 13:23:00 2024, Number of Pages: 3, Number of Words: 366, Number of Characters: 2089, Security: 0
File size
54 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
7fb39a3d7f4561c0babc19f5eb465c0201352ac4
SHA256
34562d73903ac5a63737f923492835f3bee0a0d0b3a2f7882479d88cd46efd53
MD5
d2214af2bb38c27909e5ddff085c10ab

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files

Discovery

T1497.001 antivm_queries_computername: Retrieves the computer name

Command and Control

T1071.001 wininet_https: Performs HTTP/HTTPS requests using WinInet

Other

yara_rules: Static rules
create_rpc_bindings: Creates RPC connection
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card