Managed XDR

autorecovery-save-of-attachment.asd — malware analysis report

File info

Filename
autorecovery-save-of-attachment.asd
File type
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: -535, Template: counter.ldf, Last Saved By: Admin, Revision Number: 142, Name of Creating Application: Microsoft Office Word, Total Editing Time: 1d+01:52:00, Last Printed: Tue Jan 10 15:31:00 2023, Create Time/Date: Sat Aug 6 21:34:00 2022, Last Saved Time/Date: Thu Oct 17 20:09:00 2024, Number of Pages: 2, Number of Words: 297, Number of Characters: 1699, Security: 0
File size
133 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
66407310af6ceddd004b9cd878a9894551412d42
SHA256
cb27f47cc644a9b63f2f48af3efa7224b332f7af2669ec28465ff298b2319443
MD5
4652f3b15d7337f05c56e5bd2afa5e9f

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1221 office_attached_template: Office file attempts to download a suspicious template from the Internet
T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1497.001 antivm_queries_computername: Retrieves the computer name

Other

get_policy_info: Retrieves information about a Policy object
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card