Managed XDR

1-20_1276_-autosaved-3...11575162083253264-.asd — malware analysis report

File info

Filename
1-20_1276_-autosaved-311575162083253264-.asd
File type
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1252, Title: DUDKXN, Subject: HTJEHAKP, Author: DUCWVOD-PC, Keywords: lazy, left, mutating, none, nonmutating,optional, override, postfix, precedence, prefix, Protocol, required, Comments: Etiam posuere quam ac quam. Maecenas aliquet accumsan leo. Nullam dapibus fermentum ipsum. Etiam quis quam. Integer lacinia. Nulla est. Nulla turpis magna, cursus sit amet, suscipit a, interdum id, felis. Integer vulputate sem a nibh rutrum consequat. Maecenas lorem. Pellentesque pretium., Template: Normal.dotm, Last Saved By: Dubem, Revision Number: 3, Name of Creating Application: Microsoft Office Word, Create Time/Date: Tue Oct 2 17:16:00 2018, Last Saved Time/Date: Tue Oct 2 15:25:00 2018, Number of Pages: 1, Number of Words: 0, Number of Characters: 1, Security: 0
File size
688.5 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
4a6aa80768cafe6c80a4f047fcabe84a47deb342
SHA256
d6c13fb92ed6b406ada08aba60579549dd37c65cc59ee9750cfa98bea49967fd
MD5
e94d439c738128935d570d5221a8041e

Signatures

Execution

T1064 office_macros_suspicious: Document contains suspicious macro
T1064 office_macros: The document contains macroses (total: 2)
T1064 office_macros_strings: Feature lines found in document macro
T1064 office_macros_autoexec: The document contains an auto-start macro
T1204.002 office_vb_load: Microsoft Office is loading VB DLL files (macros usage indicator)

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027 office_macros_hex_strings: Lines in hex found in document macro
T1064 office_macros_suspicious: Document contains suspicious macro
T1564 office_vba_stomping: VBA Stomping was detected in the document (the VBA source code and P-code are different)
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1497.001 antivm_queries_computername: Retrieves the computer name
T1064 office_macros: The document contains macroses (total: 2)
T1064 office_macros_strings: Feature lines found in document macro
T1064 office_macros_autoexec: The document contains an auto-start macro

Discovery

T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1497.001 antivm_queries_computername: Retrieves the computer name

Other

yara_rules: Static rules
office_summary: The document contains suspicious metadata
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card
checktokenmembership: Checks user token with CheckTokenMembership call