Managed XDR

salary_lockheed_martin...ities_confidential.doc — malware analysis report

File info

Filename
salary_lockheed_martin_job_opportunities_confidential.doc
File type
Composite Document File V2 Document, Little Endian, Os: Windows, Version 1.0, Code page: -535, Author: Mickey, Template: Normal.dotm, Revision Number: 84, Total Editing Time: 41:23, Create Time/Date: Fri Apr 24 03:18:00 2020, Last Saved Time/Date: Mon Jan 5 15:46:39 2026
File size
1.2 MB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
9ab02fe0b87dd0caf34f6ca16513c2579a91e764
SHA256
cc2447a9c93c2f0ba351e0e41c30e0fcf8f3e68225c14352b0d75159ecd7457c
MD5
9a6e7c9b4c9fed593d417bfe90aa2ac6

Signatures

Execution

T1064 office_macros_suspicious: Document contains suspicious macro
T1064 office_macros: The document contains macro
T1064 office_macros_strings: Feature lines found in document macro
T1064 office_macros_autoexec: The document contains an auto-start macro

Privilege Escalation

T1055 injection_failed: The attempt to inject into a process has failed

Defense Evasion

T1027 office_macros_entropy: The document contains a macro with high entropy (a possible sign of obfuscation)
T1064 office_macros_suspicious: Document contains suspicious macro
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1497.002 antivm_usbstor: Reads information about usbdevices from regkey
T1055 injection_failed: The attempt to inject into a process has failed
T1064 office_macros: The document contains macro
T1064 office_macros_strings: Feature lines found in document macro
T1064 office_macros_autoexec: The document contains an auto-start macro

Credential Access

T1555.004 windows_credential_manager: Acquire credentials from the Windows Credential Manager

Discovery

T1518 locates_browser: Attempts to identify where browsers are installed
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1497.002 antivm_usbstor: Reads information about usbdevices from regkey

Other

yara_rules: Static rules
network_bind: Starts servers listening at None
process_crashed: One of the processes has failed
unexpected_exception: Unexpected exception
office_summary: The document contains suspicious metadata
suspicious_network_port: Performs TCP or UDP request to non-standard port
test_check_service: Starts services
writes_data: Writes big amount of data to disk