Managed XDR

vtdl_144z7k03 — malware analysis report

File info

Filename
vtdl_144z7k03
File type
Microsoft Word 2007+
File size
35.3 KB
First seen
Last seen

Environment

w10/x86 en

Hashes

SHA1
90ece2eb231b4ee932a7b3b06ba67c50dc8dff04
SHA256
384dc360f670bb53de2f3e11ef5da5624f7fd601fa9a4742df01bb05590dd2f5
MD5
b4faee9284f66028793962b9805631e7

Signatures

Execution

T1064 office_macros: The document contains macro
T1064 office_macros_strings: Feature lines found in document macro
T1204.002 office_com_load: Microsoft Office loads COM DLL files (indicator of COM usage in macros)

Defense Evasion

T1221 office_attached_template: Office file attempts to download a suspicious template from the Internet
T1064 office_macros: The document contains macro
T1064 office_macros_strings: Feature lines found in document macro

Credential Access

T1056.001 infostealer_keylogger: Keylogger (intercepts keystrokes)

Collection

T1056.001 infostealer_keylogger: Keylogger (intercepts keystrokes)

Command and Control

T1071.001 network_http: Performs HTTP requests
T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp
T1071.001 wininet_https: Performs HTTP/HTTPS requests using WinInet

Other

creates_suspended_process: Creates suspended process
test_check_service: Starts services
suricata_alert: Malicious traffic detected