Managed XDR

vtdl_1752077574_3r8spgz3 — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl_1752077574_3r8spgz3
Тип файла
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1200, Locale ID: 2052, Author: Adminis, Template: Normal, Revision Number: 31, Total Editing Time: Mon Feb 5 16:00:00 1900, Create Time/Date: Mon May 6 06:35:00 2024, Last Saved Time/Date: Thu Dec 12 03:27:08 2024, Number of Pages: 3, Number of Words: 3575, Number of Characters: 3785, Name of Creating Application: WPS Office_12.1.0.18276_F1E327B, Security: 0
Размер файла
293.5 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
b8b82d03d4ee7b13ff99a73a8846f23bf134a244
SHA256
23be67c9fe2d6771925521b83bf289df906114512092235e44ac8081a74a9d23
MD5
a61f35dbc7425d96998bf2209fc0d8b2

Сигнатуры

Execution

T1064 office_macros: The document contains macro
T1064 office_macros_strings: Feature lines found in document macro
T1064 office_macros_autoexec: The document contains an auto-start macro
T1204.002 office_vb_load: Microsoft Office is loading VB DLL files (macros usage indicator)

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1064 office_macros: The document contains macro
T1064 office_macros_strings: Feature lines found in document macro
T1064 office_macros_autoexec: The document contains an auto-start macro
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card
checktokenmembership: Checks user token with CheckTokenMembership call