Managed XDR

simple_rtf_file_with_e..._and_cve_2018_0802.rtf — malware analysis report

File info

Filename
simple_rtf_file_with_exploit_cve_2017_11882_and_cve_2018_0802.rtf
File type
Rich Text Format data, version 1, unknown character set
File size
54.7 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
72512d49f3e49528e41f3c55701d21383b3a49fb
SHA256
24a14ec1df1d1be1b24ef7af7b5ca86e80be66f84493b489d07a21e8823cbee8
MD5
d89fbb7c741190986757169ecc7f7834

Signatures

Execution

T1203 exploit_CVE_2017_11882: Exploits CVE-2017-11882 vulnerability
T1059.003 suspicious_process: Spawns a suspicious process
T1204.002 office_vb_load: Microsoft Office is loading VB DLL files (macros usage indicator)

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files

Discovery

T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1083 checks_recent_files: Attempt to check recently opened files through registry

Other

yara_rules: Static rules
runs_utility_without_cmdline: Runs system utility without arguments (non-typical usage)
process_crashed: One of the processes has failed
unexpected_exception: Unexpected exception
create_rpc_bindings: Creates RPC connection
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card
checktokenmembership: Checks user token with CheckTokenMembership call