Managed XDR

word-embeddings-oleobject1.bin (Mimikatz) — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
word-embeddings-oleobject1.bin
Тип файла
Composite Document File V2 Document, Cannot read section info
Размер файла
982.5 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
cce1f77378ef09ba2a66223b26e8137463386781
SHA256
8a5b6b79af1492aa2cda81321a7fba27d3305a804372994b1dd040dd7deeda39
MD5
ffd1ee49e21b28fe927b092c7bb9d809

Вредоносное ПО

  • Mimikatz

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1550.003 pass_the_ticket: Pass The Ticket is detected
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Lateral Movement

T1550.003 pass_the_ticket: Pass The Ticket is detected

Other

yara_rules: Static rules
pe_overlay: PE file contains overlay
valid_authenticode: The digital signature has been verified

Похожие отчёты