Managed XDR

videos_aus_sat_1_mediathek_downloaden.js — malware analysis report

File info

Filename
videos_aus_sat_1_mediathek_downloaden.js
File type
ASCII text, with very long lines, with CRLF line terminators
File size
2.3 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
cd666a29d2da27e48a147ea41d91eed12811b2ae
SHA256
08179d3b3eb454136719824418a039db0da8868ccc8958efb791c648f61ecb51
MD5
006978b6b10360018fb61b992d273e92

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
break_limit_exceeded: Warning: function calls limit has been exceeded
checktokenmembership: Checks user token with CheckTokenMembership call