Managed XDR

wrf-77d8abf3-173b-49f6...9b0a-8cdc833edfa2-.tmp — malware analysis report

File info

Filename
wrf-77d8abf3-173b-49f6-9b0a-8cdc833edfa2-.tmp
File type
Composite Document File V2 Document, Cannot read section info
File size
32 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
e560558b39c1654f5fbe3246d287eb86520505c5
SHA256
d9f30d7aa6b1224981abc04fcc228e9e06c0cd3d14d5c875727b6b396a80ab47
MD5
a4a9414e9f219c18e0a0644bb5429085

Signatures

Execution

T1059.007 bad_js: Suspicious Javascript file

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
message_box: Displays a message
error_drawtext: An error occured while executing the file
checktokenmembership: Checks user token with CheckTokenMembership call