Managed XDR

winword.exe — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
winword.exe
Тип файла
PE32 executable (GUI) Intel 80386, for MS Windows
Размер файла
898 KB
Первое обнаружение
Последнее обнаружение

Окружение

w10/x86 en

Хеши

SHA1
9e0e51cfa2be2c25ab737d079c8d3ff2d18070f6
SHA256
ee9730e2d6afb79a7e0be1c21d9ab46a0eaddb98c8fd62f2b93760f754edb1e9
MD5
24b0e644ad8ba43a6cfa627d3a4a1af7

Сигнатуры

Execution

T1203 office_write_exe: Office document dropped an executable file
T1559 suspicious_process: Spawns a suspicious process

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_polymorphic: Creates a modified copy of itself
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1070 stealth_window: A process created a hidden window
T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antivm_queries_computername: Retrieves the computer name

Other

creates_many_processes: Spawns a lot of processes (over 70)
executes_dropped_exe: Executes dropped exe files
no_graphical_activity: No graphic activity
creates_suspended_process: Creates suspended process
break_limit_exceeded: Warning: function calls limit has been exceeded
suspicious_network_port: Performs TCP or UDP request to non-standard port
writes_data: Writes big amount of data to disk
pe_overlay: PE file contains overlay