Managed XDR

fw-kpmg-tax-walkthroug...ntrols-placeholder.msg — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
fw-kpmg-tax-walkthrough-corporation-tax-rdec-annual-ye-controls-placeholder.msg
Тип файла
CDFV2 Microsoft Outlook Message
Размер файла
5.1 MB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
c87761f12d6cddf0e407bfb220a46485b8ce7913
SHA256
b38a3eb24b48091ebf8342491e52bd8b8e19e3994477ffe07aabb857bcc6529c
MD5
cb9a66ffeff0ee5401f4f6d24ba9ae18

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card