Managed XDR

autorecovery-save-of-mimikatz_word.docx.asd (Mimikatz) — malware analysis report

File info

Filename
autorecovery-save-of-mimikatz_word.docx.asd
File type
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1252, Template: Normal.dotm, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Total Editing Time: 01:00, Create Time/Date: Mon Apr 22 10:15:00 2024, Last Saved Time/Date: Mon Apr 22 10:16:00 2024, Number of Pages: 1, Number of Words: 2, Number of Characters: 18, Security: 0
File size
1002.5 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
e50f3a4e9cc33960a138c61bdbc38415a6311799
SHA256
87b5c5e1c0b509e16d32fb3e7f29447c1c9ca9a9dfd5f893eb6c4c1a34dbb4c9
MD5
4391915c256a42ace9b65650d21b1fc3

Malwares

  • Mimikatz

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1497.001 antivm_queries_computername: Retrieves the computer name
T1550.003 pass_the_ticket: Pass The Ticket is detected
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antivm_queries_computername: Retrieves the computer name

Lateral Movement

T1550.003 pass_the_ticket: Pass The Ticket is detected

Other

yara_rules: Static rules
office_embedded: Office document contains embedded executable file(s)
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card
pe_overlay: PE file contains overlay
valid_authenticode: The digital signature has been verified

Related reports