Managed XDR

vtdl_dhm00urs — malware analysis report

File info

Filename
vtdl_dhm00urs
File type
Rich Text Format data, version 1, ANSI
File size
63.9 KB
First seen
Last seen

Environment

win7/x64 en

Hashes

SHA1
afe7a226854363201f5dfbd88e03f68298bf7bd1
SHA256
d780981c43232309fd37024d5a85c044a1948bd0710fa2adba7d8b7ce3979c03
MD5
d0f33489ff0be35008ef6f407ee1b935

Signatures

Execution

T1203 office_write_exe: Office document dropped an executable file

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1055 injection_failed: The attempt to inject into a process has failed

Defense Evasion

T1497 checks_firmware: Attempts to read firmware information (potentially for evasion)
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1055 injection_failed: The attempt to inject into a process has failed

Discovery

T1497 checks_firmware: Attempts to read firmware information (potentially for evasion)
T1083 checks_recent_files: Attempt to check recently opened files through registry
T1135 server_share_info: Retrieves information about each shared resource on a server
T1082 checks_firmware: Attempts to read firmware information (potentially for evasion)

Other

office_embedded: Office document contains embedded executable file(s)
static_pe_anomaly: The PE file structure contains anomalies
creates_exe: Creates executable files in the file system
create_rpc_bindings: Creates RPC connection
has_pdb: This executable file has a PDB path
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card
yara_rules: Static rules