Managed XDR

word-embeddings-oleobject1.bin — malware analysis report

File info

Filename
word-embeddings-oleobject1.bin
File type
Composite Document File V2 Document, Cannot read section info
File size
144 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
0dd7a26c12e3452d3a01851a765a289921fdd8c2
SHA256
0997f8c0ecf32670d555c7a6039ed38cdb5591b47bc46a424cdf185923f49f60
MD5
e79fe247edbeaf3bcef55811c9526677

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files

Command and Control

T1071.001 wininet_https: Performs HTTP/HTTPS requests using WinInet

Other

yara_rules: Static rules
networkdyndns_checkip: Connects to a Dynamic DNS domain
no_graphical_activity: No graphic activity
create_rpc_bindings: Creates RPC connection
get_policy_info: Retrieves information about a Policy object
pe_overlay: PE file contains overlay