Managed XDR

wrf-00f4d079-220c-4690...bb36-620ea1af377d-.tmp — malware analysis report

File info

Filename
wrf-00f4d079-220c-4690-bb36-620ea1af377d-.tmp
File type
Composite Document File V2 Document, Cannot read section info
File size
64 KB
First seen
Last seen

Environment

winxp/x86 en

Hashes

SHA1
e50c6949c99cef545ecab0fd6efab93ea3729b9c
SHA256
c72068fa9e61ab29ff9d7e6e1b1e6a917c0169692d1379a7e309eb0cabf72b77
MD5
4396fde9432c5f6b2923d67593f41ddf

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
creates_in_programdata: Creates files in the ProgramData directory