Managed XDR

qdir-2024-03-28-12.57.12-001.doc — malware analysis report

File info

Filename
qdir-2024-03-28-12.57.12-001.doc
File type
Rich Text Format data, version 1, unknown character set
File size
5.3 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
82fec4f8cfcd6a3ce48c1179408b1c5fbd260c1c
SHA256
0243f967c58a60d667cfc864c7685254ad4ae230bcc9f9f399ec3b67bd5674e2
MD5
820f3913de8814f2a00f815a75c47993

Signatures

Execution

T1203 exploit_CVE_2017_11882: Exploits CVE-2017-11882 vulnerability
T1203 office_exploit_http: The document exhibits suspicious behaviour (performs HTTP requests)
T1106 susp_callbacks: Suspicious usage of some WinAPI with callbacks

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 unnamed_memory_regions_contains_pe: One or several unnamed memory regions are PE files
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files

Discovery

T1083 checks_recent_files: Attempt to check recently opened files through registry

Command and Control

T1071.001 office_exploit_http: The document exhibits suspicious behaviour (performs HTTP requests)
T1071.001 network_cnc_http: Suspicious HTTP traffic
T1071.004 office_exploit_dns: The document exhibits suspicious behaviour (performs DNS requests)
T1071.001 network_http: Performs HTTP requests
T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp
T1102.003 cloud_onedrive: Connects to cloud services of Onedrive (potentially for malicious payload delivery)

Other

yara_rules: Static rules
executes_dropped_exe: Executes dropped exe files
creates_exe: Creates executable files in the file system
dbatloader_behaviour: DBatLoader/ModiLoader behaviour
suspicious_process_network: Unusual process network activity detected
suspicious_process: Spawns a suspicious process
process_crashed: One of the processes has failed
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card
suricata_alert: Malicious traffic detected