Managed XDR

autorecovery-save-of-sample.asd — malware analysis report

File info

Filename
autorecovery-save-of-sample.asd
File type
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1252, Title: Invoice Template.docx, Author: McCoy, Jolene I [EOADV], Template: Normal.dotm, Last Saved By: Windows User, Revision Number: 2, Name of Creating Application: Microsoft Office Word, Total Editing Time: 01:00, Last Printed: Fri Jun 5 13:38:00 2015, Create Time/Date: Wed Dec 4 05:04:00 2019, Last Saved Time/Date: Wed Dec 4 05:04:00 2019, Number of Pages: 2, Number of Words: 75, Number of Characters: 431, Security: 0
File size
184 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
c8d850a606ab7a8894cf1ca39b9824eebd1f6365
SHA256
9defbf4447bd5156cd5a63ef2bb0ab81bbdda01c36064d6b7780a67c0e57d3e6
MD5
920e0bf1f33a57dae6b719d25bdf44d6

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antivm_queries_computername: Retrieves the computer name

Other

yara_rules: Static rules
office_embedded: Office document contains embedded executable file(s)
message_box: Displays a message
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card