Managed XDR

wrf-1b2beb66-355f-4004...9514-7284d5be2c69-.tmp — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
wrf-1b2beb66-355f-4004-9514-7284d5be2c69-.tmp
Тип файла
Composite Document File V2 Document, Cannot read section info
Размер файла
1.7 MB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
fb764782120fcea0865bf78cdeb0d3a3a85ebdc3
SHA256
085662403edce2593631c48c628b46341600ff2fa4902ec5dff2f253ea722264
MD5
542e5de15865608774e2d0f84ff3c628

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1036.001 invalid_authenticode: Digital signature of the executable file has failed the verification
T1027.002 packer_upx: The executable file is compressed using UPX
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1057 process_interest: Enumerates processes
T1497.001 antivm_queries_computername: Retrieves the computer name

Command and Control

T1071.001 network_http: Performs HTTP requests

Other

yara_rules: Static rules
opens_document: Opens office documents
creates_doc: Creates (office) documents in the file system
pe_overlay: PE file contains overlay