Managed XDR

cve-2023-38831-poc.rar — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
cve-2023-38831-poc.rar
Тип файла
Zip archive data, at least v2.0 to extract
Размер файла
174.9 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
8a8f871c554c210a92322c7dad052a3cbd97fd2b
SHA256
f14a709638f178eb4bc78f59947e71ba38c51fc023be40ac4b95863cb4d996b4
MD5
ec853547e099baf26bd40a324d477c8a

Сигнатуры

Execution

T1204.002 mimics_extension: Attempts to mimic the file extension
T1203 suspicious_msapp: Suspicious execution of Microsoft Application (possible exploitation)

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1036 mimics_extension: Attempts to mimic the file extension
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
pdf_compressed_stream: Contains an object with compressed stream
office_links: Office file contains external links
checktokenmembership: Checks user token with CheckTokenMembership call