Managed XDR

xl-embeddings-oleobject1.bin (Mimikatz) — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
xl-embeddings-oleobject1.bin
Тип файла
Composite Document File V2 Document, Cannot read section info
Размер файла
1.2 MB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x64 en

Хеши

SHA1
b60168d96a405fb6a1047f4defa043ecaaae9ee3
SHA256
f359f8818ee93cb78b46a9261d1a42f7c59d85a224ef0e95ebbbde3cde0bd670
MD5
0ca50cf1c59a3aaccc87982e492542eb

Вредоносное ПО

  • Mimikatz

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1550.003 pass_the_ticket: Pass The Ticket is detected
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Lateral Movement

T1550.003 pass_the_ticket: Pass The Ticket is detected

Other

yara_rules: Static rules
pe_overlay: PE file contains overlay
valid_authenticode: The digital signature has been verified

Похожие отчёты