Managed XDR

scratch-zoo-2025-04-18...34e416f76be8c977480441 — malware analysis report

File info

Filename
scratch-zoo-2025-04-18-6bb0b6475234e416f76be8c977480441
File type
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 1200, Locale ID: 2052, Author: Adminis, Template: Normal, Last Saved By: V, Revision Number: 2, Create Time/Date: Tue Aug 15 00:27:00 2023, Last Saved Time/Date: Wed Apr 16 02:50:28 2025, Last Printed: Wed Oct 9 07:37:55 2024, Number of Pages: 4, Number of Words: 227, Number of Characters: 1295, Name of Creating Application: WPS Office_11.8.2.10321_F1E327B, Security: 0
File size
31.5 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
c22beba7ef0fefe5148b0442e693d9425aa14d97
SHA256
a73e9f697730803999d47763f46ff0db114c143d84c80729e57aa88bb02b0b57
MD5
6bb0b6475234e416f76be8c977480441

Signatures

Execution

T1064 office_macros: The document contains macro
T1064 office_macros_autoexec: The document contains an auto-start macro
T1204.002 office_vb_load: Microsoft Office is loading VB DLL files (macros usage indicator)
T1106 susp_callbacks: Suspicious usage of some WinAPI with callbacks

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1064 office_macros: The document contains macro
T1064 office_macros_autoexec: The document contains an auto-start macro
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
get_policy_info: Retrieves information about a Policy object
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card
checktokenmembership: Checks user token with CheckTokenMembership call