Managed XDR

microsoft-office-365-p...er-3.3.1_2baksa.ws.rar — malware analysis report

File info

Filename
microsoft-office-365-proplus-online-installer-3.3.1_2baksa.ws.rar
File type
RAR archive data, v5
File size
7.5 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
ec90316bcdb7bd66c8c41cf82a86f24f8b2ae821
SHA256
11dda75aad2a549e3911c7e59aced11ece6364c68cb1847ab2e90dd8d5c73764
MD5
808673e15c7c191f3db83bb72558f7d2

Signatures

Execution

T1059.001 suspicious_powershell: Creates suspicious powershell process
T1059.001 suspicious_process: Spawns a suspicious process
T1047 has_wmi: Executes one or several WMI requests
T1059.003 suspicious_batch: Suspicious batch

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1518 locates_browser: Attempts to identify where browsers are installed

Command and Control

T1102.003 references_github: Contains links to cloud services of Github (potentially for malicious payload delivery)

Other

yara_rules: Static rules
creates_many_processes: Spawns a lot of processes (over 70)
codepage: Checks the system code page
has_pdb: This executable file has a PDB path
break_limit_exceeded: Warning: function calls limit has been exceeded
creates_in_programdata: Creates files in the ProgramData directory
test_check_service: Starts services
checktokenmembership: Checks user token with CheckTokenMembership call
pe_overlay: PE file contains overlay
many_files_in_archive: The archive contains more than 5 files