Managed XDR

document-autosaved-311882043120613616-.asd — malware analysis report

File info

Filename
document-autosaved-311882043120613616-.asd
File type
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: -535, Title: , Author: Admin, Template: almost.3dmf, Last Saved By: Dmytro, Revision Number: 2, Name of Creating Application: Microsoft Office Word, Total Editing Time: Sun Feb 15 21:42:00 9767, Last Printed: Tue Jun 24 14:58:00 2025, Create Time/Date: Tue Jun 24 15:02:00 2025, Last Saved Time/Date: Tue Jun 24 15:02:00 2025, Number of Pages: 2, Number of Words: 592, Number of Characters: 3379, Security: 0
File size
104.5 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
d522300673dcb96c205c05bf7c281830eee2a9d5
SHA256
855ee3da25b1fad1f5ce9c929b2be54edf256c62f2769bfaf0219439c33a12b5
MD5
eef9b4eeb5504e825a54422227ffb34d

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1221 office_attached_template: Office file attempts to download a suspicious template from the Internet
T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antivm_queries_computername: Retrieves the computer name

Other

get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card
yara_rules: Static rules