Managed XDR

vikings.doc — malware analysis report

File info

Filename
vikings.doc
File type
Composite Document File V2 Document, Little Endian, Os 0, Version: 3.10, Template: C:\OFFICE\WINWORD\PLANTILL\NORMAL.DOT, Title: The term Vikings is used broadly to describe the Scandinavian peoples between AD 800 and 1100; more properly it refers to those who left their homes to trade and raid along the shores of the Baltic, North, and Irish seas and along the rivers of eastern an, Author: Rafael Carrasco Santa Cruz, Last Saved By: Rafael Carrasco Santa Cruz, Create Time/Date: Wed Jan 28 20:39:00 1998, Last Saved Time/Date: Wed Jan 28 20:39:00 1998, Number of Words: 1795, Number of Characters: 9488, Name of Creating Application: Microsoft Word 6.0, Number of Pages: 3, Revision Number: 3, Security: 0
File size
28.5 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
783a72756fede15fa66fc6d6db41f16cc4ddad42
SHA256
e95046188a9927e1784ffff41b28ee1d06ec1e0abd3be82261d5b4d569b7712e
MD5
d1ae9341850beb0bfa3d89babae506d6

Signatures

Execution

T1204.002 office_vb_load: Microsoft Office is loading VB DLL files (macros usage indicator)

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1096 persistence_ads: Creates Alternate Data Stream (ADS)
T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files

Discovery

T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1083 checks_recent_files: Attempt to check recently opened files through registry

Other

yara_rules: Static rules
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card