VTI Score
92 / 100
|
|
VTI Database Version | 2.6 |
VTI Rule Match Count | 11 |
VTI Rule Type | Documents |
![]() | Network | |
![]() | Connect to TOR hidden service | |
Connect to TOR hidden service at "fbbkvm7ezghq4dx3.onion.link". | ||
Connect to TOR hidden service at "fbbkvm7ezghq4dx3.onion.link/msbus24.exe". | ||
![]() | Download data | |
Url "fbbkvm7ezghq4dx3.onion.link/msbus24.exe". | ||
![]() | Perform DNS request | |
Resolve "fbbkvm7ezghq4dx3.onion.link". | ||
Resolve "onion.link". | ||
![]() | Connect to remote host | |
Outgoing TCP connection to host "188.166.203.69:80". | ||
Outgoing TCP connection to host "103.198.0.2:443". | ||
![]() | Connect to HTTP server | |
Remote address "fbbkvm7ezghq4dx3.onion.link/msbus24.exe". | ||
![]() | Process | |
![]() | Create system object | |
Create mutex with name "Global\.net clr networking". | ||
![]() | VBA Macro | |
![]() | Execute application | |
Shell Environ("temp") + "\test.bat", vbHide | ||
![]() | Execute macro on specific worksheet event | |
Execute macro on "Open Document" event. | ||
- | Anti Analysis | |
- | Browser | |
- | Device | |
- | OS | |
- | File System | |
- | Hide Tracks | |
- | Information Stealing | |
- | Injection | |
- | Kernel | |
- | Masquerade | |
- | PE | |
- | Persistence | |
- | User | |
- | YARA |