Managed XDR

standard_celeration_excel.xls (ZLoader) — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
standard_celeration_excel.xls
Тип файла
Composite Document File V2 Document, Little Endian, Os: MacOS, Version 4.14, Code page: 10000, Title: SCCFB (daily count per minute), Subject: Standard Chart Templates, Author: Owen White, Stuart Harder, & Scott Born, Keywords: celeration line, bounce, record floor, acceleration, deceleration, total possible, Comments: Original Template designed by Owen White 19?? Chart formatting by Scott Born and Additional functionality and program support for data entry and celeration lines by Stuart Harder. Owen White provided protocol for the Median Slope trend line method and Stuart Harder converted the method into code for the template. Bounce line analysis by Stuart Harder., Last Saved By: Martell, Kim, Revision Number: 1, Name of Creating Application: Microsoft Macintosh Excel, Last Printed: Wed Nov 5 17:34:03 2008, Create Time/Date: Tue Sep 12 22:41:17 2000, Last Saved Time/Date: Wed Jul 10 00:54:59 2024, Security: 0
Размер файла
2.2 MB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
e8b449a5ac5171611f0769e05395a9cf36ab1de0
SHA256
0823a646caf6c13cbe934ad2b7894e00ac6f6b8b984d2eb8dd891bea94a812c2
MD5
3d86fc4f81e27f48b137bb552d5478a3

Вредоносное ПО

  • ZLoader

Сигнатуры

Execution

T1064 office_macros_hidden: Document contains suspicious Excel 4.0 macro
T1064 office_macros: The document contains macro
T1204.002 office_vb_load: Microsoft Office is loading VB DLL files (macros usage indicator)

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1064 office_macros_hidden: Document contains suspicious Excel 4.0 macro
T1064 office_macros: The document contains macro
T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1497 windows_enumthread: Attempts to enumerate windows using EnumThreadWindows and SendMessage for text obtaining
T1497.002 async_mouse: Watches for mouse clicks using GetAsyncKeyState to detect human activity
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files

Discovery

T1083 checks_recent_files: Attempt to check recently opened files through registry
T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1497 windows_enumthread: Attempts to enumerate windows using EnumThreadWindows and SendMessage for text obtaining
T1497.002 async_mouse: Watches for mouse clicks using GetAsyncKeyState to detect human activity
T1082 windows_enumthread: Attempts to enumerate windows using EnumThreadWindows and SendMessage for text obtaining

Other

yara_rules: Static rules
office_summary: The document contains suspicious metadata
create_rpc_bindings: Creates RPC connection
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card
checktokenmembership: Checks user token with CheckTokenMembership call

Похожие отчёты