Managed XDR

okokok.docx-autosaved-...11045681803431872-.asd — malware analysis report

File info

Filename
okokok.docx-autosaved-311045681803431872-.asd
File type
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: -535, Author: Bo Long Trn Vit, Template: Normal.dotm, Last Saved By: Bo Long Trn Vit, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Total Editing Time: 28:00, Create Time/Date: Sat May 4 14:42:00 2024, Last Saved Time/Date: Sat May 4 14:45:00 2024, Number of Pages: 2, Number of Words: 13, Number of Characters: 77, Security: 0
File size
336.5 KB
First seen
Last seen

Environment

win7/x64 en

Hashes

SHA1
387a7733dd2d7b7631b021021f282e5764cb13aa
SHA256
599702396c648f9ebcff3f0c982f98f7aefb8d47d26e37dff6c8bfbbc535c799
MD5
29f55275aeacdcddc6087d5df30cab0e

Signatures

Execution

T1053.005 creates_tasks: Creates a delayed task using Task Scheduler
T1059.001 suspicious_powershell: Creates suspicious powershell process
T1047 has_wmi: Executes one or several WMI requests

Persistence

T1053.005 creates_tasks: Creates a delayed task using Task Scheduler

Privilege Escalation

T1053.005 creates_tasks: Creates a delayed task using Task Scheduler
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1564.001 stealth_file: Creates hidden or system files
T1497.001 antivm_disk_size: Checks the amount of free disk space
T1222 icacls: May obtain or change Discretionary access control lists (DACLs)
T1497 checks_firmware: Attempts to read firmware information (potentially for evasion)
T1497.001 antivm_queries_computername: Retrieves the computer name
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1562.001 windows_defender_add_exclusion: Adds a path to Microsoft Defender exclusion list
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1552 cookie_files: Accesses cookie files
T1555.003 cookie_files: Accesses cookie files

Discovery

T1497.001 antivm_disk_size: Checks the amount of free disk space
T1082 has_wmi: Executes one or several WMI requests
T1518 locates_browser: Attempts to identify where browsers are installed
T1497 checks_firmware: Attempts to read firmware information (potentially for evasion)
T1497.001 antivm_queries_computername: Retrieves the computer name
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1135 server_share_info: Retrieves information about each shared resource on a server
T1082 checks_firmware: Attempts to read firmware information (potentially for evasion)

Command and Control

T1071.001 network_http: Performs HTTP requests
T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp
T1071.001 wininet_https: Performs HTTP/HTTPS requests using WinInet

Other

yara_rules: Static rules
office_embedded: Office document contains embedded executable file(s)
executes_dropped_exe: Executes dropped exe files
creates_in_windows: Creates files in the Windows directory
modifies_certs: Attempts to generate or modify system certificates
creates_exe: Creates executable files in the file system
process_crashed: One of the processes has failed
unexpected_exception: Unexpected exception
create_rpc_bindings: Creates RPC connection
require_administrator: Requests administrator privileges
has_pdb: This executable file has a PDB path
creates_suspended_process: Creates suspended process
break_limit_exceeded: Warning: function calls limit has been exceeded
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card