Managed XDR

a.hta — malware analysis report

File info

Filename
a.hta
File type
HTML document, ASCII text, with very long lines, with CRLF line terminators
File size
16.6 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
3654fa8087b2d47332e726cfea446da0c18999fc
SHA256
1b087b9b2b3eed38189d87dfce5742a7b6b452e7c69e0677c59255d47086e741
MD5
66fcbb4208a959505d798d39baef4443

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
get_policy_info: Retrieves information about a Policy object