Managed XDR

1.doc (Emotet) — malware analysis report

File info

Filename
1.doc
File type
Composite Document File V2 Document, Little Endian, Os: Windows, Version 1.0, Code page: -535, Title: Natus., Author: Baptiste Morel, Template: Normal.dotm, Revision Number: 2, Total Editing Time: 00:14, Create Time/Date: Tue Sep 15 19:31:00 2020, Last Saved Time/Date: Sat May 31 08:59:31 2025
File size
74 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
af4718bc39a23dd4bdd0fd368f53cc0e6673db60
SHA256
d35c44206d6bf2b9e078bac81691332d301345d43b29b3abc2967ae2391350e3
MD5
e1c052f9313a64124f1ce6455a1e6bf0

Malwares

  • Emotet

Signatures

Execution

T1064 office_macros: The document contains macroses (total: 2)
T1064 office_macros_autoexec: The document contains an auto-start macro
T1204.002 office_vb_load: Microsoft Office is loading VB DLL files (macros usage indicator)

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1064 office_macros: The document contains macroses (total: 2)
T1064 office_macros_autoexec: The document contains an auto-start macro
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
office_summary: The document contains suspicious metadata
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card
checktokenmembership: Checks user token with CheckTokenMembership call

Related reports