Managed XDR

c-users-user-appdata-l...ntent.word-wrd0001.tmp — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
c-users-user-appdata-local-microsoft-windows-inetcache-content.word-wrd0001.tmp
Тип файла
Microsoft Word 2007+
Размер файла
227.7 KB
Первое обнаружение
Последнее обнаружение

Окружение

winxp/x86 en

Хеши

SHA1
096c75b7c4b435818eb87d3f52824a3491f03001
SHA256
1589260525c3a2f5eb9ed7bc110f0a980912d424047e5b23b6b5c3070c426e7b
MD5
c8370c73d66cdb2b42731730c405d824

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
creates_in_programdata: Creates files in the ProgramData directory