Managed XDR

mdx-microsoft_office_3...ne_installer_3.2.6.rar — malware analysis report

File info

Filename
mdx-microsoft_office_365_proplus_-_online_installer_3.2.6.rar
File type
RAR archive data, v2.0, os: Unix
File size
7.4 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
008a48a2f422f8090ee516f007f37e3acaf8830c
SHA256
fc53e9b50bb5fae923f5f11ea58d95187435d17d2ff24568ef9733f7d3d371bd
MD5
70fc00ce2ad8848d10e1321f23a01ab7

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1027.002 packer_entropy: Probably contains compressed or encrypted data

Discovery

T1518 locates_browser: Attempts to identify where browsers are installed

Other

yara_rules: Static rules
codepage: Checks the system code page
has_pdb: This executable file has a PDB path
checktokenmembership: Checks user token with CheckTokenMembership call
pe_overlay: PE file contains overlay