Managed XDR

vtdl_1745208539_xpfvi0gt — malware analysis report

File info

Filename
vtdl_1745208539_xpfvi0gt
File type
Microsoft Word 2007+
File size
561.4 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
d295047eae7f951e968888f6bd11be4f5763e4ec
SHA256
6dba59870e2e814ba960ae01b70c7b2cee59f91eaf3165793a2375606568297c
MD5
3363fb3b8e3859b041cd5fc8a1d48792

Signatures

Initial Access

T1192 html_urls: HTML-document downloads a file

Execution

T1059.003 suspicious_process: Spawns a suspicious process
T1059.005 mshta_vbscript: Runs VBScript using mshta

Persistence

T1574.011 persistence_services: Modifies Services registry key
T1543.003 persistence_services: Modifies Services registry key

Privilege Escalation

T1574.011 persistence_services: Modifies Services registry key
T1543.003 persistence_services: Modifies Services registry key
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1218.005 mshta_vbscript: Runs VBScript using mshta
T1574.011 persistence_services: Modifies Services registry key
T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1552 cookie_files: Accesses cookie files
T1555.003 cookie_files: Accesses cookie files

Discovery

T1082 uses_windows_utilities: Uses Windows utilities for basic Windows functionality
T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1083 checks_recent_files: Attempt to check recently opened files through registry

Command and Control

T1102.003 references_github: Contains links to cloud services of Github (potentially for malicious payload delivery)

Impact

T1489 stops_service: Stops Windows services
T1489 net_stop: Stops services through the use of net stop

Other

creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
office_links: Office file contains external links
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card
checktokenmembership: Checks user token with CheckTokenMembership call