Managed XDR

c-users-user-appdata-l...ntent.word-wrd0001.tmp — malware analysis report

File info

Filename
c-users-user-appdata-local-microsoft-windows-inetcache-content.word-wrd0001.tmp
File type
Microsoft Word 2007+
File size
225.3 KB
First seen
Last seen

Environment

winxp/x86 en

Hashes

SHA1
032679ea9a3b147183ae7bb1af883ef9145b54e7
SHA256
a9da06f06c3e9df37c78105a832b9c0a45135bb99b9eccd1d79293446b858240
MD5
abb48c1f20481a7c139583d886339051

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
creates_in_programdata: Creates files in the ProgramData directory