Managed XDR

useh.hta — malware analysis report

File info

Filename
useh.hta
File type
HTML document, ASCII text, with very long lines, with CRLF line terminators
File size
53.3 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
8f3cc71acfe9f5613f2a8d146aeae09703d86238
SHA256
48b8c5703ff73125cb373b9a05e959ea467038a1391f368a863b7734b92f44ae
MD5
2dcd99cda4b7d8dac7f6d5fc746d73ac

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files

Discovery

T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Other

yara_rules: Static rules
get_policy_info: Retrieves information about a Policy object