Managed XDR

vtdl_1786918676_alujk4rr — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl_1786918676_alujk4rr
Тип файла
Composite Document File V2 Document, Little Endian, Os: Windows, Version 5.1, Code page: 1252, Title: 4, Author: CARRIZO CHAPARRO, Template: Normal, Last Saved By: JOSE, Revision Number: 53, Name of Creating Application: Microsoft Office Word, Total Editing Time: 20:25:00, Last Printed: Thu Jun 29 00:19:00 2006, Create Time/Date: Tue Jan 31 14:48:00 2006, Last Saved Time/Date: Sun Jul 2 00:50:00 2006, Number of Pages: 25, Number of Words: 5074, Number of Characters: 27912, Security: 0
Размер файла
5.2 MB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x64 en

Хеши

SHA1
5812cb6f534f111788f2b4f1d5ac42c1e30f5124
SHA256
95b0ecd501eec79ab0bc018e53c185904d300465cb35880a73d905e8df9f90b0
MD5
77f23565efc9f32a41795f68d0567c29

Сигнатуры

Execution

T1064 office_macros: The document contains macroses (total: 4)
T1064 office_macros_autoexec: The document contains an auto-start macro

Persistence

T1574.011 persistence_services: Modifies Services registry key
T1543.003 persistence_services: Modifies Services registry key

Privilege Escalation

T1574.011 persistence_services: Modifies Services registry key
T1543.003 persistence_services: Modifies Services registry key
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1562 dep_disable: Disables DEP
T1574.011 persistence_services: Modifies Services registry key
T1564 office_vba_stomping: VBA Stomping was detected in the document (the VBA source code and P-code are different)
T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1064 office_macros: The document contains macroses (total: 4)
T1064 office_macros_autoexec: The document contains an auto-start macro

Discovery

T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1083 checks_recent_files: Attempt to check recently opened files through registry

Other

office_embedded: Office document contains embedded executable file(s)
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
origin_langid: Unconventional language of the executable file
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card
yara_rules: Static rules
dotnet_suspicious_cultureidentifier: Dotnet program contains invalid CultureIdentifier