Managed XDR

vtdl_1733880508_xrckahj4 — malware analysis report

File info

Filename
vtdl_1733880508_xrckahj4
File type
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 936, Author: Gaojunwei, Last Saved By: kl, Name of Creating Application: WPS Office, Last Printed: Thu Nov 11 14:18:00 2021, Create Time/Date: Thu Nov 11 13:58:39 2021, Last Saved Time/Date: Fri Nov 12 01:06:07 2021, Security: 0
File size
52.5 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
3ed96d0f164884447e0147cf5ec7e8faca44a056
SHA256
a083e13cfec96214c476795b84df76f0f600d75a56aef2c85a137f6f65bf0b7a
MD5
00b98f0a7ed16f64ef6b79007663b5a7

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1564 office_vba_stomping: VBA Stomping was detected in the document (the VBA source code and P-code are different)
T1497 windows_enumthread: Attempts to enumerate windows using EnumThreadWindows and SendMessage for text obtaining
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497 windows_enumthread: Attempts to enumerate windows using EnumThreadWindows and SendMessage for text obtaining
T1082 windows_enumthread: Attempts to enumerate windows using EnumThreadWindows and SendMessage for text obtaining

Other

yara_rules: Static rules
office_summary: The document contains suspicious metadata
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card