Managed XDR

wrf-86e465f0-360f-4ca8...80c8-f492183d7d7a-.tmp — malware analysis report

File info

Filename
wrf-86e465f0-360f-4ca8-80c8-f492183d7d7a-.tmp
File type
Composite Document File V2 Document, Cannot read section info
File size
16 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
966ecdb28ee2ae95b11ee446998483a9e4ae29d6
SHA256
a2a80442f1e55ee7956bbea5044f0a59fd94c2db233d945a12c687f09a02bef6
MD5
2ee001484f013b498c798335a4036a94

Signatures

Execution

T1059.001 suspicious_powershell: Creates suspicious powershell process
T1059.001 suspicious_process: Spawns a suspicious process
T1059.001 url_cmdline: Cmdline of process contains URL
T1059.003 url_cmdline: Cmdline of process contains URL

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1218 suspicious_cmdline: Executes a suspicious command
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Command and Control

T1071.001 network_cnc_http: Suspicious HTTP traffic
T1071.001 network_http: Performs HTTP requests

Other

yara_rules: Static rules
creates_exe: Creates executable files in the file system
dns_without_resolve: DNS query without a response
checktokenmembership: Checks user token with CheckTokenMembership call
suricata_alert: Malicious traffic detected