Managed XDR

p019846645.rtf — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
p019846645.rtf
Тип файла
ISO-8859 text, with very long lines, with CRLF, CR, LF line terminators
Размер файла
172.6 KB
Первое обнаружение
Последнее обнаружение

Окружение

w10/x64 en

Хеши

SHA1
fc1c841e17af35dd55010d8cd2d486a7a5eff7db
SHA256
c6dfd1b9e066944d4c3a00b096a0238e9ea192101e05a5748a8b7e2173ad1664
MD5
06920a595cd3e21160cd213ab8e7d718

Сигнатуры

Execution

T1204.002 office_com_load: Microsoft Office loads COM DLL files (indicator of COM usage in macros)

Defense Evasion

T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization

Credential Access

T1555.004 windows_credential_manager: Acquire credentials from the Windows Credential Manager

Discovery

T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization

Other

yara_rules: Static rules
office_suspicious_data: Office file contains suspicious data
test_check_service: Starts services