Managed XDR

wrf-1b2beb66-355f-4004...9514-7284d5be2c69-.tmp — malware analysis report

File info

Filename
wrf-1b2beb66-355f-4004-9514-7284d5be2c69-.tmp
File type
Composite Document File V2 Document, Cannot read section info
File size
1.7 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
fb764782120fcea0865bf78cdeb0d3a3a85ebdc3
SHA256
085662403edce2593631c48c628b46341600ff2fa4902ec5dff2f253ea722264
MD5
542e5de15865608774e2d0f84ff3c628

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1036.001 invalid_authenticode: Digital signature of the executable file has failed the verification
T1027.002 packer_upx: The executable file is compressed using UPX
T1497.001 antivm_queries_computername: Retrieves the computer name
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1057 process_interest: Enumerates processes
T1497.001 antivm_queries_computername: Retrieves the computer name

Command and Control

T1071.001 network_http: Performs HTTP requests

Other

yara_rules: Static rules
opens_document: Opens office documents
creates_doc: Creates (office) documents in the file system
pe_overlay: PE file contains overlay