Managed XDR

word-embeddings-oleobject1.bin (Mimikatz) — malware analysis report

File info

Filename
word-embeddings-oleobject1.bin
File type
Composite Document File V2 Document, Cannot read section info
File size
982.5 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
cce1f77378ef09ba2a66223b26e8137463386781
SHA256
8a5b6b79af1492aa2cda81321a7fba27d3305a804372994b1dd040dd7deeda39
MD5
ffd1ee49e21b28fe927b092c7bb9d809

Malwares

  • Mimikatz

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1550.003 pass_the_ticket: Pass The Ticket is detected
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1027.002 packer_entropy: Probably contains compressed or encrypted data

Lateral Movement

T1550.003 pass_the_ticket: Pass The Ticket is detected

Other

yara_rules: Static rules
pe_overlay: PE file contains overlay
valid_authenticode: The digital signature has been verified

Related reports