Managed XDR

autorecovery-save-of-design.docm.asd — malware analysis report

File info

Filename
autorecovery-save-of-design.docm.asd
File type
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1252, Template: Normal.dotm, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Total Editing Time: 21:00, Create Time/Date: Fri Sep 18 04:42:00 2015, Last Saved Time/Date: Thu Oct 1 23:18:00 2015, Number of Pages: 1, Number of Words: 37, Number of Characters: 214, Security: 0
File size
1 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
7dba2eded6e2201e8709f2c01649e73caf6c167a
SHA256
3af85f7f5f57075e313476e551e1af00397808a97b2c110939c64b75e172ce71
MD5
c0ed14f06477beb6aa177d5ae7dc95c6

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1036.001 invalid_authenticode: Digital signature of one or several attached files has failed to be verified
T1027.002 packer_upx: The executable file is compressed using UPX
T1497.001 antivm_queries_computername: Retrieves the computer name
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1057 process_interest: Enumerates processes
T1497.001 antivm_queries_computername: Retrieves the computer name

Command and Control

T1071.001 network_http: Performs HTTP requests

Other

yara_rules: Static rules
office_embedded: Office document contains embedded executable file(s)
opens_document: Opens office documents
creates_doc: Creates (office) documents in the file system
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card
pe_overlay: PE file contains overlay