Managed XDR

c-users-user-desktop-u...0435-vasileva.doc-copy — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
c-users-user-desktop-u0420-u0435-u0437-u044e-u043c-u0435-vasileva.doc-copy
Тип файла
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1252, Author: Tester, Template: Normal, Last Saved By: george, Revision Number: 68, Name of Creating Application: Microsoft Office Word, Total Editing Time: 28:00, Create Time/Date: Tue Dec 2 14:30:00 2014, Last Saved Time/Date: Sat Jan 11 06:04:00 2025, Number of Pages: 1, Number of Words: 29, Number of Characters: 171, Security: 0
Размер файла
879 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
8bf59d315c6acb16f89b5149130d1c6dfd3ea127
SHA256
c649b3d89f94c36cd78b4ee56e05e57e43cc4204a66269e2a69eec38f0f28e1b
MD5
8d70b86ba7264977951614761f4c5f6b

Сигнатуры

Execution

T1204.002 office_strings: Office file contains suspicious strings

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1036.001 invalid_authenticode: Digital signature of one or several attached files has failed to be verified
T1027.002 packer_upx: The executable file is compressed using UPX
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1057 process_interest: Enumerates processes
T1497.001 antivm_queries_computername: Retrieves the computer name

Command and Control

T1071.001 network_http: Performs HTTP requests

Other

yara_rules: Static rules
office_embedded: Office document contains embedded executable file(s)
opens_document: Opens office documents
creates_doc: Creates (office) documents in the file system
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card
pe_overlay: PE file contains overlay