Managed XDR

k-kb_sample-415e11fbaa...b508013e13fad7e66f44b9 — malware analysis report

File info

Filename
k-kb_sample-415e11fbaab508013e13fad7e66f44b9
File type
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 936, Author: user, Template: Normal.wpt, Last Saved By: zhang doumiao, Revision Number: 2, Name of Creating Application: Microsoft Office Word, Total Editing Time: 03:00, Create Time/Date: Fri Apr 24 07:36:00 2020, Last Saved Time/Date: Mon May 20 02:37:00 2024, Number of Pages: 2, Number of Words: 192, Number of Characters: 1101, Security: 0
File size
76 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
551665d629f595f5c7d79c15fd4c3e66143ce29d
SHA256
328c6dbae7cbe9a81e5dbe237049b110bc01d9aaedd5302c37ed0b5e5156c9a8
MD5
415e11fbaab508013e13fad7e66f44b9

Signatures

Execution

T1064 office_macros: The document contains macro
T1064 office_macros_autoexec: The document contains an auto-start macro
T1204.002 office_vb_load: Microsoft Office is loading VB DLL files (macros usage indicator)

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1064 office_macros: The document contains macro
T1064 office_macros_autoexec: The document contains an auto-start macro
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
error_drawtext: An error occured while executing the file
get_policy_info: Retrieves information about a Policy object
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card
checktokenmembership: Checks user token with CheckTokenMembership call