Managed XDR

wrd0005.tmp — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
wrd0005.tmp
Тип файла
Rich Text Format data, version 1, unknown character set
Размер файла
693 KB
Первое обнаружение
Последнее обнаружение

Окружение

winxp/x86 en

Хеши

SHA1
4fb42a5074d7bd83b18310e0a7ea622e2c42b2bb
SHA256
d734b117ac6cc84ba94781fd0dff247a439d472595bfad7c950fa3d9d254b17b
MD5
160ee582594b851f5067ca035e708fb6

Сигнатуры

Execution

T1203 office_exploit_http: The document exhibits suspicious behaviour (performs HTTP requests)
T1559 suspicious_process: Spawns a suspicious process
T1559 dde_img: Office document has an INCLUDEPICTURE with external link

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread

Credential Access

T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files

Command and Control

T1071.001 office_exploit_http: The document exhibits suspicious behaviour (performs HTTP requests)
T1071.004 office_exploit_dns: The document exhibits suspicious behaviour (performs DNS requests)
T1071.001 network_http: Performs HTTP requests

Other

yara_rules: Static rules
dead_host: Connects to IP addresses that do not respond to requests
office_summary: The document contains suspicious metadata
creates_in_programdata: Creates files in the ProgramData directory