Managed XDR

wrf-612aa678-0345-47d4...8ded-d341c3f60e60-.tmp — malware analysis report

File info

Filename
wrf-612aa678-0345-47d4-8ded-d341c3f60e60-.tmp
File type
Composite Document File V2 Document, Cannot read section info
File size
32 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
161009cc08ebaf915eab659a7c894cc4fce5e7bf
SHA256
6b6d755125c3345232b155a8aa680ab7854b443e975109e952ea7f04cde513ff
MD5
78d34fd656414f1291b10034852e9c8c

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
dead_dotnet_downloader: Dead hosted dotnet downloader
dead_host: Connects to IP addresses that do not respond to requests
dead_host_suspicious: Connects to IP addresses with suspicious port that do not respond (possible Meterpreter)
no_graphical_activity: No graphic activity
dotnet_import_unmanaged_code: Dotnet program statically imports unmanaged functions/modules
dotnet_obfuscated: Dotnet program is potentially obfuscated
get_policy_info: Retrieves information about a Policy object
dotnet_use_suspicious_functions: Dotnet program potentially uses suspicious functions/modules
dotnet_suspicious_entrypoint: Dotnet program has suspicious entrypoint