Managed XDR

word-embeddings-oleobject1.bin — malware analysis report

File info

Filename
word-embeddings-oleobject1.bin
File type
Composite Document File V2 Document, Cannot read section info
File size
26 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
cc52334bd26ea139678747c3054a58ae455b59ac
SHA256
11c7b9fb21af6cb08ced5ee0bd197fc5c072450e4b5121f8375c61b1f25806c5
MD5
1a132ba03ac5092e41e3acf36f45978e

Signatures

Execution

T1059.007 pdf_js: PDF contains JavaScript

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.002 async_mouse: Watches for mouse clicks using GetAsyncKeyState to detect human activity
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.002 async_mouse: Watches for mouse clicks using GetAsyncKeyState to detect human activity

Command and Control

T1071.001 network_http: Performs HTTP requests
T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp

Other

yara_rules: Static rules
suricata_alert: Malicious traffic detected
pdf_page: Contains only one page
pdf_compressed_stream: Contains an object with compressed stream
get_policy_info: Retrieves information about a Policy object