Managed XDR

vtdl_1751469738_62uj0913 — malware analysis report

File info

Filename
vtdl_1751469738_62uj0913
File type
Composite Document File V2 Document, Little Endian, Os: Windows, Version 5.1, Code page: 1200, Author: Billion Dol, Number of Characters: 18, Create Time/Date: Wed Dec 20 07:56:00 2017, Last Saved By: Billion Dol, Last Saved Time/Date: Wed Dec 20 07:58:00 2017, Name of Creating Application: Microsoft O, Number of Pages: 1, Revision Number: 3, Security: 0, Template: Normal, Total Editing Time: 02:00, Number of Words: 3
File size
76 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
0c5b9b230880c24e0b4067a907d9ed560d2cf321
SHA256
0a2b46e87c5ab1b00ab2cbe4c65c3f3f5d7b78337e954ac1088a4ab1567259e9
MD5
04dd67e7c0116bf826e16dd58eb7658e

Signatures

Execution

T1059 network_wscript_downloader: Wscript.exe initiated network communication
T1059.005 obfuscated_vbs: Detected obfuscated VBS

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027 obfuscated_vbs: Detected obfuscated VBS
T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files

Discovery

T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Command and Control

T1071 network_wscript_downloader: Wscript.exe initiated network communication
T1071.001 network_http: Performs HTTP requests
T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp

Other

yara_rules: Static rules
office_embedded: Office document contains embedded executable file(s)
create_rpc_bindings: Creates RPC connection
message_box: Displays a message
error_drawtext: An error occured while executing the file
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card
checktokenmembership: Checks user token with CheckTokenMembership call
suricata_alert: Malicious traffic detected