Managed XDR

2_5375261324538293848-...11779632516151952-.asd — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
2_5375261324538293848-autosaved-311779632516151952-.asd
Тип файла
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: -535, Title: , Template: naughty.51hsc, Last Saved By: admin, Revision Number: 4, Name of Creating Application: Microsoft Office Word, Total Editing Time: 07:00, Last Printed: Tue Aug 8 18:43:00 2023, Create Time/Date: Tue Aug 8 18:39:00 2023, Last Saved Time/Date: Tue Aug 8 18:43:00 2023, Number of Pages: 1, Number of Words: 229, Number of Characters: 1306, Security: 0
Размер файла
55.5 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
ef3fab2ef197357118b7cc17c92e48c163d7e109
SHA256
db2dd9dde0f3d221e545521729a6bbbbe508209f8cb68f9b67d507137ccca697
MD5
7b35bdbc03d3d5b9d971da3f92c45bd0

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1221 office_attached_template: Office file attempts to download a suspicious template from the Internet
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1497.001 antivm_queries_computername: Retrieves the computer name

Discovery

T1497.001 antivm_queries_computername: Retrieves the computer name

Other

yara_rules: Static rules
get_policy_info: Retrieves information about a Policy object
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card