Managed XDR

______-20_o___o__-20__...11270924054756768-.asd — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
______-20_o___o__-20____-autosaved-311270924054756768-.asd
Тип файла
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1252, Author: Tester, Template: Normal.dotm, Last Saved By: Tester, Revision Number: 4, Name of Creating Application: Microsoft Office Word, Total Editing Time: 02:00, Create Time/Date: Tue Dec 2 14:31:00 2014, Last Saved Time/Date: Wed Dec 3 12:34:00 2014, Number of Pages: 1, Number of Words: 22, Number of Characters: 132, Security: 0
Размер файла
720 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
bdc1d198ff528db5a2a468be59f004efdfb7fde2
SHA256
af2f01949332c4f4830717aef3739ec1fc57d319bdb47ee4c64a5ab02a0f8b38
MD5
27b10ce370f63e482b82d5bbdae1f86e

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1036.001 invalid_authenticode: Digital signature of one or several attached files has failed to be verified
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1057 process_interest: Enumerates processes
T1497.001 antivm_queries_computername: Retrieves the computer name

Command and Control

T1071.001 network_http: Performs HTTP requests

Other

yara_rules: Static rules
office_embedded: Office document contains embedded executable file(s)
opens_document: Opens office documents
creates_doc: Creates (office) documents in the file system
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card
pe_overlay: PE file contains overlay