Managed XDR

wrf-95e02fab-8b62-4854...a92d-7b069042b231-.tmp — malware analysis report

File info

Filename
wrf-95e02fab-8b62-4854-a92d-7b069042b231-.tmp
File type
Composite Document File V2 Document, Cannot read section info
File size
688 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
d5ef98439dea6fb2f0e6657f0b68b083f0a4362d
SHA256
3f13be99bca5ceb5f157654393eb2f1281707f50214cf660505ab1f2109f85f1
MD5
bed4ae5907de67e3683fc2be854ad7bc

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497 windows_enumthread: Attempts to enumerate windows using EnumThreadWindows and SendMessage for text obtaining
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497 windows_enumthread: Attempts to enumerate windows using EnumThreadWindows and SendMessage for text obtaining
T1082 windows_enumthread: Attempts to enumerate windows using EnumThreadWindows and SendMessage for text obtaining

Other

yara_rules: Static rules
create_rpc_bindings: Creates RPC connection
break_limit_exceeded: Warning: function calls limit has been exceeded
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card