Managed XDR

scratch-zoo-2025-03-07...113b60c8b482841285c0ee — malware analysis report

File info

Filename
scratch-zoo-2025-03-07-9a6a79cc04113b60c8b482841285c0ee
File type
Rich Text Format data, version 1, unknown character set
File size
8.3 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
3721b5022539a63ab482f159915a541456edd346
SHA256
1ca4e0f4c2a93aecb839f2973b4610749d9f0b84e03e6a43cb40054b6e039bbd
MD5
9a6a79cc04113b60c8b482841285c0ee

Signatures

Execution

T1204.002 office_vb_load: Microsoft Office is loading VB DLL files (macros usage indicator)

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1497.001 antivm_queries_computername: Retrieves the computer name
T1497.002 async_mouse: Watches for mouse clicks using GetAsyncKeyState to detect human activity
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1497.001 antivm_queries_computername: Retrieves the computer name
T1497.002 async_mouse: Watches for mouse clicks using GetAsyncKeyState to detect human activity
T1135 server_share_info: Retrieves information about each shared resource on a server
T1083 checks_recent_files: Attempt to check recently opened files through registry

Other

yara_rules: Static rules
create_rpc_bindings: Creates RPC connection
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card