Managed XDR

webp-policy-eyjtdgf0zw...0yuoesf0ngbplvbo8roxfy — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
webp-policy-eyjtdgf0zw1lbnqiolt7iljlc291cmnlijoiahr0chm6ly9tzwrpys1jzg4uyxrsyxnzawfulmnvbs91cy13zx...zhqwimxu-afwbusywrzrt6astqksxqwc3nm53lnummh9vqlzsoxn8hlp9z2kf6gdyxo0wkap3n550yuoesf0ngbplvbo8roxfy
Тип файла
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 1252, Author: Cyber, Template: Normal, Last Saved By: Cyber, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Total Editing Time: 03:00, Create Time/Date: Tue May 16 01:19:00 2017, Last Saved Time/Date: Tue May 16 01:22:00 2017, Number of Pages: 1, Number of Words: 326, Number of Characters: 1859, Security: 0
Размер файла
160 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
344ac8db1a02f54e670a38e511d7d452b6c800db
SHA256
c172049fb3390efb7f7420b8b36e9bb62e61ca8fe774320ff8c6956fa3f212d3
MD5
277b20606d237bd4bbcc9f6808d0daef

Сигнатуры

Execution

T1064 office_macros_suspicious: Document contains suspicious macro
T1204 office_dotnet_load: Microsoft Office loads .NET assembly or DLL files (indicator of suspicious MS Office activity)
T1204.002 office_vb_load: Microsoft Office is loading VB DLL files (macros usage indicator)
T1064 office_macros: The document contains macroses (total: 2)
T1064 office_macros_strings: Feature lines found in document macro
T1064 office_macros_autoexec: The document contains an auto-start macro

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027 office_macros_hex_strings: Lines in hex found in document macro
T1497.001 antivm_network_adapters: Checks NIC addresses
T1064 office_macros_suspicious: Document contains suspicious macro
T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1064 office_macros: The document contains macroses (total: 2)
T1064 office_macros_strings: Feature lines found in document macro
T1064 office_macros_autoexec: The document contains an auto-start macro

Discovery

T1497.001 antivm_network_adapters: Checks NIC addresses
T1497.001 antivm_queries_computername: Retrieves the computer name

Command and Control

T1102.003 cloud_dropbox: Connects to cloud services of Dropbox (potentially for malicious payload delivery)

Other

yara_rules: Static rules
creates_exe: Creates executable files in the file system
macro_uses_system_namespace: Macro uses System namespace classes (possibly to run malicious code)
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card
checktokenmembership: Checks user token with CheckTokenMembership call
suricata_alert: Malicious traffic detected