Managed XDR

2024-06-13-9031419da65...c1a27ced62291c294.xlsx — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
2024-06-13-9031419da652ea359a93b540d21a2b2dec0275348c0157ec1a27ced62291c294.xlsx
Тип файла
Microsoft Excel 2007+
Размер файла
649.1 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
f6bbb1e3ce73bdd0452495c7119c6422a50a09ee
SHA256
9031419da652ea359a93b540d21a2b2dec0275348c0157ec1a27ced62291c294
MD5
7de20d3b9b0d1c4d5baee659391af41f

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497 windows_enumthread: Attempts to enumerate windows using EnumThreadWindows and SendMessage for text obtaining
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497 windows_enumthread: Attempts to enumerate windows using EnumThreadWindows and SendMessage for text obtaining
T1082 windows_enumthread: Attempts to enumerate windows using EnumThreadWindows and SendMessage for text obtaining

Other

yara_rules: Static rules
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card