Managed XDR

unknown — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
unknown
Тип файла
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1200, Locale ID: 2052, Title: _EeO, Author: use, Template: Norm, Last Saved By: Adminis, Revision Number: 2, Create Time/Date: Wed May 15 03:18:00 2019, Last Saved Time/Date: Thu Jun 13 00:08:41 2019, Last Printed: Mon May 30 08:22:00 2011, Number of Pages: 1, Number of Words: 69, Number of Characters: 395, Name of Creating Application: Microsoft O, Security: 0
Размер файла
40 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
aad8e07f1645ed373210878a5bcb26e2de2adecc
SHA256
b23229a9669b821b9108bf8ca69d10051a6def34dae824ba79140d8f44537eff
MD5
0b22a54aa131fea0ffceb6546fe6843a

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card