Managed XDR

4ce39251817198bbec7b84...e363f0c1e05558ef1.xlsx — malware analysis report

File info

Filename
4ce39251817198bbec7b84782507394e7d68bfe3a79b89be363f0c1e05558ef1.xlsx
File type
Microsoft Excel 2007+
File size
237.9 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
90865548339cd404adf60ddf54b04b2ad503f8c6
SHA256
ac606d3aa3ce4d35a96dafff16328be11264793d68932528365b04c8f8593b9b
MD5
82b4df4edd806d5a9c74000d8cf580b1

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497 windows_enumthread: Attempts to enumerate windows using EnumThreadWindows and SendMessage for text obtaining
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497 windows_enumthread: Attempts to enumerate windows using EnumThreadWindows and SendMessage for text obtaining
T1082 windows_enumthread: Attempts to enumerate windows using EnumThreadWindows and SendMessage for text obtaining

Other

yara_rules: Static rules
xlsb_macrosheet: Contains xlsb macro sheet
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card