Managed XDR

vtdl_snycudgq — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl_snycudgq
Тип файла
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1200, Locale ID: 2052, Author: 'I13801, Template: Normal, Last Saved By: ;, Revision Number: 1, Total Editing Time: Sat Dec 30 16:00:00 1899, Create Time/Date: Wed Oct 29 12:08:00 2014, Last Saved Time/Date: Thu Sep 7 09:10:56 2023, Last Printed: Thu Sep 7 08:25:22 2023, Number of Pages: 6, Number of Words: 2410, Number of Characters: 2450, Name of Creating Application: WPS Office_11.1.0.14309_F1E327B, Security: 0
Размер файла
148.5 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
89cd240393a213d6dd056123deef1f3db81389cf
SHA256
f561fbf9028899ee9072eadfa0d20e174a5a1e4316abba26818f367518d8dfe7
MD5
feda457ca8387c2a8d80eafd21fac70d

Сигнатуры

Execution

T1064 office_macros: The document contains macro
T1064 office_macros_autoexec: The document contains an auto-start macro
T1204.002 office_vb_load: Microsoft Office is loading VB DLL files (macros usage indicator)

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1064 office_macros: The document contains macro
T1064 office_macros_autoexec: The document contains an auto-start macro
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card
checktokenmembership: Checks user token with CheckTokenMembership call