Managed XDR

word-embeddings-oleobject1.bin (Metasploit) — malware analysis report

File info

Filename
word-embeddings-oleobject1.bin
File type
Composite Document File V2 Document, Cannot read section info
File size
13.5 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
732690420f0946eeadf852be11227586d5f1ec22
SHA256
ed88b319d2a40a628f65d5345487e572aa9323a49af4d721610b0a1ecd217caa
MD5
5121b118db18b3c852281dc8dd70ccb7

Malwares

  • Metasploit

Signatures

Execution

T1059.005 obfuscated_vbs: Detected obfuscated VBS
T1059 wscript_info_discovery: Collects info about system with Wscript.Shell

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027 obfuscated_vbs: Detected obfuscated VBS
T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1070 stealth_window: A process created a hidden window
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1033 wscript_info_discovery: Collects info about system with Wscript.Shell

Other

yara_rules: Static rules
creates_exe: Creates executable files in the file system
create_process_failed: Could not start the process
no_graphical_activity: No graphic activity
message_box: Displays a message
error_drawtext: An error occured while executing the file
get_policy_info: Retrieves information about a Policy object
checktokenmembership: Checks user token with CheckTokenMembership call

Related reports