Managed XDR

c-users-user-appdata-l...dfee2298b7c41b89ea.tmp — malware analysis report

File info

Filename
c-users-user-appdata-local-temp-dfee2298b7c41b89ea.tmp
File type
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 936, Author: ZYY, Template: Normal.dotm, Last Saved By: Aliyun User, Revision Number: 22, Name of Creating Application: Microsoft Office Word, Total Editing Time: 06:43:00, Create Time/Date: Wed Apr 13 08:50:00 2011, Last Saved Time/Date: Wed Apr 24 02:04:00 2024, Number of Pages: 28, Number of Words: 908, Number of Characters: 5176, Security: 0
File size
8.1 MB
First seen
Last seen

Environment

win7/x64 en

Hashes

SHA1
304f7e6449a14ee20220f2792402d4965eb5cd02
SHA256
14f47b54694604ebc970d2b423e42df4d484397efea725e61d7f39ac3164de6d
MD5
44705248f328057e1369dfc5f52c2797

Signatures

Persistence

T1574 dropper_dll: Creates DLL, which is then loaded into the process

Privilege Escalation

T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.001 antivm_disk_size: Checks the amount of free disk space
T1497.001 antivm_network_adapters: Checks NIC addresses
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1480 system_default_lang_id_present: Checks the system language
T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1497 evasion_diskenum: Sandbox evasion using enumeration of partitions
T1497 checks_firmware: Attempts to read firmware information (potentially for evasion)
T1497.001 antivm_queries_computername: Retrieves the computer name
T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Credential Access

T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files

Discovery

T1497.001 antivm_disk_size: Checks the amount of free disk space
T1497.001 antivm_network_adapters: Checks NIC addresses
T1083 checks_recent_files: Attempt to check recently opened files through registry
T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1497 evasion_diskenum: Sandbox evasion using enumeration of partitions
T1497 checks_firmware: Attempts to read firmware information (potentially for evasion)
T1497.001 antivm_queries_computername: Retrieves the computer name
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1135 server_share_info: Retrieves information about each shared resource on a server
T1082 checks_firmware: Attempts to read firmware information (potentially for evasion)

Other

office_embedded: Office document contains embedded executable file(s)
creates_exe: Creates executable files in the file system
executes_dropped_exe: Executes dropped exe files
process_crashed: One of the processes has failed
unsigned_driver_drop: Sample is not signed and drops a device driver
create_rpc_bindings: Creates RPC connection
pdf_compressed_stream: Contains an object with compressed stream
has_pdb: This executable file has a PDB path
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
office_links: Office file contains external links
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card
pe_overlay: PE file contains overlay
yara_rules: Static rules