Managed XDR

scratch-zoo-2025-04-08...b5309926d02f369a94d84a — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
scratch-zoo-2025-04-08-dde3ee40bdb5309926d02f369a94d84a
Тип файла
Composite Document File V2 Document, Cannot read section info
Размер файла
13.9 MB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
90a030d4369a038bf6bf293a4346b0da7a669d8e
SHA256
d9a4dfd53e068f0914fe446ff652f61c435e7941efcc1fff0c5285aa60964824
MD5
dde3ee40bdb5309926d02f369a94d84a

Сигнатуры

Execution

T1064 office_macros: The document contains macroses (total: 5)
T1064 office_macros_autoexec: The document contains an auto-start macro

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1497.002 async_mouse: Watches for mouse clicks using GetAsyncKeyState to detect human activity
T1064 office_macros: The document contains macroses (total: 5)
T1064 office_macros_autoexec: The document contains an auto-start macro
T1027 office_macros_entropy: The document contains a macro with high entropy (a possible sign of obfuscation)
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1497.002 async_mouse: Watches for mouse clicks using GetAsyncKeyState to detect human activity
T1083 checks_recent_files: Attempt to check recently opened files through registry

Other

yara_rules: Static rules
office_summary: The document contains suspicious metadata
get_policy_info: Retrieves information about a Policy object
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card