Managed XDR

c-users-user-appdata-l...tshewillbehappy-1-.doc — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
c-users-user-appdata-local-microsoft-windows-temporary-internet-files-content.ie5-i9clic0d-wanthea...tofthingsneedtodobutsheisverybeautifulgirlwhoilovedheralotmygirlsheis___iwantshewillbehappy-1-.doc
Тип файла
Rich Text Format data, version 1, unknown character set
Размер файла
64.7 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
2dd25fc6e2ac92c41c127575de44fafbd353e1ff
SHA256
e26ce79ac9736d5103e528cf4b55cfb61dbc419c01a662e42147536ad810b2ef
MD5
4415a7be0a155d61eb245b749e7859f2

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antivm_queries_computername: Retrieves the computer name

Other

yara_rules: Static rules
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card