Managed XDR

wrf-418ddc38-51d3-4a93...87d1-e13fe8239688-.tmp — malware analysis report

File info

Filename
wrf-418ddc38-51d3-4a93-87d1-e13fe8239688-.tmp
File type
Composite Document File V2 Document, Cannot read section info
File size
98.8 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
7838cf358429ba3012325ee066c1c1e3e4733e2c
SHA256
3df9bdd01717aa7f3b0c4634659793fbdb9151497bc641b36eb466df6adb447f
MD5
f518414fc64c925faf35bf4983931426

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1056.001 infostealer_keylogger: Keylogger (intercepts keystrokes)

Collection

T1056.001 infostealer_keylogger: Keylogger (intercepts keystrokes)

Other

yara_rules: Static rules
creates_in_windows: Creates files in the Windows directory
creates_exe: Creates executable files in the file system
process_crashed: One of the processes has failed
no_graphical_activity: No graphic activity