Managed XDR

xl-embeddings-oleobject1.bin (XWorm) — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
xl-embeddings-oleobject1.bin
Тип файла
Composite Document File V2 Document, Cannot read section info
Размер файла
20.5 KB
Первое обнаружение
Последнее обнаружение

Окружение

w10/x86 en

Хеши

SHA1
cdada53ac5c2e83cb3f9bd77beb60ff4a712f903
SHA256
9f59b3b66dadcaa5fd2353e6cc323b32912e91afcc08822604fa99b8cf9c266a
MD5
3e7f4d8a577bf8aa7040cac0329533cc

Вредоносное ПО

  • XWorm

Сигнатуры

Execution

T1047 has_wmi: Executes one or several WMI requests

Privilege Escalation

T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.001 antivm_disk_size: Checks the amount of free disk space
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1056.001 infostealer_keylogger: Keylogger (intercepts keystrokes)

Discovery

T1497.001 antivm_disk_size: Checks the amount of free disk space
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1518.001 wmi_check_av: Uses WMI to check for installed antivirus software
T1082 has_wmi: Executes one or several WMI requests
T1497.001 antivm_queries_computername: Retrieves the computer name

Collection

T1056.001 infostealer_keylogger: Keylogger (intercepts keystrokes)

Exfiltration

T1022 encrypts_pc_info: Collects and encrypts information about the computer (possibly for exfiltration)

Other

yara_rules: Static rules
suricata_alert: Malicious traffic detected
critical_process: Makes the process critical to the system (the system shuts down when it's terminated)
no_graphical_activity: No graphic activity
create_rpc_bindings: Creates RPC connection
dotnet_import_unmanaged_code: Dotnet program statically imports unmanaged functions/modules
suspicious_network_port: Performs TCP or UDP request to non-standard port
checktokenmembership: Checks user token with CheckTokenMembership call
dotnet_downloader_possible_network_problem: Dotnet program possibly has network problem

Похожие отчёты