Managed XDR

1936f62aeaf55a41a386db...11551940606324576-.asd — malware analysis report

File info

Filename
1936f62aeaf55a41a386dbc293050acec8c4616d16f7539588-autosaved-311551940606324576-.asd
File type
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1252, Author: User, Template: Normal.dotm, Last Saved By: Windows User, Revision Number: 2, Name of Creating Application: Microsoft Office Word, Create Time/Date: Mon Oct 17 04:40:00 2016, Last Saved Time/Date: Mon Oct 17 04:40:00 2016, Number of Pages: 7, Number of Words: 1202, Number of Characters: 6853, Security: 0
File size
71 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
a35ff83f047e8843ffcba17e55a06c7744314deb
SHA256
0fe4e36c102389c9f0ddc03e881a69f25538b6f1dd876b9588a29e0e6ee56aab
MD5
8791e63f653549c7f8df57ee97665ff5

Signatures

Execution

T1203 office_exploit_crash: Microsoft Office process crashes (failed exploitation of a vulnerability is possible)

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antivm_queries_computername: Retrieves the computer name

Other

yara_rules: Static rules
get_policy_info: Retrieves information about a Policy object
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card