Managed XDR

home-farm-anteroom-eef...c2c74c2a072200f06f8d2e — malware analysis report

File info

Filename
home-farm-anteroom-eef-4e1-eef4e14658d49d009378701662d650d8540e91cb6ec2c74c2a072200f06f8d2e
File type
Microsoft Word 2007+
File size
179.5 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
e48469990623f3c61e22a7a62905f977820ca83d
SHA256
eef4e14658d49d009378701662d650d8540e91cb6ec2c74c2a072200f06f8d2e
MD5
e8b9dbd39f532e64a850f6f9f244a8f7

Signatures

Execution

T1064 office_macros_suspicious: Document contains suspicious macro
T1064 office_macros: The document contains macro
T1064 office_macros_strings: Feature lines found in document macro

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1221 office_attached_template: Office file downloads a suspicious template from the Internet
T1064 office_macros_suspicious: Document contains suspicious macro
T1064 office_macros: The document contains macro
T1064 office_macros_strings: Feature lines found in document macro
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
office_links: Office file contains external links