Managed XDR

wrf-fe1938c1-aaeb-45e0...8274-61e25cbf4744-.tmp — malware analysis report

File info

Filename
wrf-fe1938c1-aaeb-45e0-8274-61e25cbf4744-.tmp
File type
Composite Document File V2 Document, Cannot read section info
File size
843.3 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
ef4778790deadb3a0417bf9a2b6f75dc2271d734
SHA256
34831ef5343015d6aa3a8bcb7a082452b677e6642748a927a3779618aca6ec3c
MD5
7c7691fd820b958b4d757a73554128c1

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_upx: The executable file is compressed using UPX
T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1027.002 packer_entropy: Probably contains compressed or encrypted data

Discovery

T1057 process_interest: Enumerates processes
T1497.001 antivm_queries_computername: Retrieves the computer name

Command and Control

T1071.001 network_http: Performs HTTP requests

Other

yara_rules: Static rules
opens_document: Opens office documents
creates_doc: Creates (office) documents in the file system