Managed XDR

autorecovery-save-of-b...interactive_v1.rtf.asd — malware analysis report

File info

Filename
autorecovery-save-of-b801.73391374_290_fiches_de_programmation_interactive_v1.rtf.asd
File type
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1252, Author: Mendes, Fabrice 11/14/2022, Template: intranet1.dot, Last Saved By: Christophe De Nicola, Revision Number: 2, Name of Creating Application: Microsoft Office Word, Create Time/Date: Mon Dec 16 16:04:00 2024, Last Saved Time/Date: Mon Dec 16 16:04:00 2024, Number of Pages: 1, Number of Words: 150, Number of Characters: 857, Security: 0
File size
80 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
8e87d60e363e2e87e75c9e73e0b454bfcae6e747
SHA256
9e9b7bb1c0aafa77dee27a5a034ced23b6082ad15ee26e66e328547a4be69e6b
MD5
992cbf5b3c1cdd45dcc4d294f755eb8f

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1221 office_attached_template: Office file attempts to download a suspicious template from the Internet
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1497.001 antivm_queries_computername: Retrieves the computer name

Discovery

T1497.001 antivm_queries_computername: Retrieves the computer name

Other

get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card