Managed XDR

c-users-user-desktop-doc13453431.doc-copy — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
c-users-user-desktop-doc13453431.doc-copy
Тип файла
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1252, Title: WPZXSQMALQ, Subject: ADTOL, Author: PPPXUAJOFD-PC, Keywords: lazy, left, mutating, none, nonmutating,optional, override, postfix, precedence, prefix, Protocol, required, Comments: Etiam posuere quam ac quam. Maecenas aliquet accumsan leo. Nullam dapibus fermentum ipsum. Etiam quis quam. Integer lacinia. Nulla est. Nulla turpis magna, cursus sit amet, suscipit a, interdum id, felis. Integer vulputate sem a nibh rutrum consequat. Maecenas lorem. Pellentesque pretium., Template: Normal, Last Saved By: george, Revision Number: 2, Name of Creating Application: Microsoft Office Word, Total Editing Time: 01:00, Create Time/Date: Thu Oct 4 16:05:00 2018, Last Saved Time/Date: Wed Jan 22 14:14:00 2025, Number of Pages: 1, Number of Words: 0, Number of Characters: 5, Security: 0
Размер файла
60 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
38cb226dd575b8a1e8085d919eea42da56be81ed
SHA256
a2fc0d3a433268700f88a8513459b371000679285b149334261a80e917bd3886
MD5
aed47c521b50792991494e0d5efd3958

Сигнатуры

Execution

T1059.001 suspicious_powershell: Suspicious document behaviour (creates powershell process)
T1059.001 suspicious_process: Spawns a suspicious process
T1064 office_macros_suspicious: Document contains suspicious macro
T1064 office_macros: The document contains macroses (total: 2)
T1064 office_macros_strings: Feature lines found in document macro
T1064 office_macros_autoexec: The document contains an auto-start macro
T1204.002 office_vb_load: Microsoft Office is loading VB DLL files (macros usage indicator)
T1059.001 url_cmdline: Cmdline of process contains URL
T1059.003 url_cmdline: Cmdline of process contains URL

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027 office_macros_hex_strings: Lines in hex found in document macro
T1064 office_macros_suspicious: Document contains suspicious macro
T1564 office_vba_stomping: VBA Stomping was detected in the document (the VBA source code and P-code are different)
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1064 office_macros: The document contains macroses (total: 2)
T1064 office_macros_strings: Feature lines found in document macro
T1064 office_macros_autoexec: The document contains an auto-start macro
T1070 stealth_window: A process created a hidden window

Other

yara_rules: Static rules
creates_exe: Creates executable files in the file system
dns_without_resolve: DNS query without a response
office_summary: The document contains suspicious metadata
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card
checktokenmembership: Checks user token with CheckTokenMembership call