Managed XDR

scratch-zoo-2025-04-02...02dbe260e9334901773f5c — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
scratch-zoo-2025-04-02-3b8e1a1d8c02dbe260e9334901773f5c
Тип файла
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 1200, Locale ID: 2052, Title: qhttp://ww, Subject: qhttp://ww, Author: qhttp://ww, Keywords: qhttp://ww, Comments: qhttp://ww, Template: Normal, Last Saved By: X, Revision Number: 3, Create Time/Date: Sun Sep 16 15:09:00 2012, Last Saved Time/Date: Sat Sep 21 02:28:34 2013, Number of Pages: 4, Number of Words: 292, Number of Characters: 1670, Name of Creating Application: Microsoft O, Security: 0
Размер файла
109.3 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
ec9ebd50c322c72da27427d82230914f030a2845
SHA256
f3b68cc55d5862d56bf607ba5b53dfc664297de70c12159f66b2293bd982a5e9
MD5
3b8e1a1d8c02dbe260e9334901773f5c

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card