Managed XDR

87ca136c6ed3436ce6d0d2...46a3221249ad534c5d.eml — malware analysis report

File info

Filename
87ca136c6ed3436ce6d0d25add78accfb276ef3c8e66fa46a3221249ad534c5d.eml
File type
data
File size
181.6 KB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
7e1d520a0d548d9f0fae6702af161d2b7228b86a
SHA256
1e47d187c9bb32286189af55761003604ea514de15366ce084647ac1800d7f9f
MD5
7b15fd4a09d30c9705d54e03dd1b9066

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
dns_without_resolve: DNS query without a response
no_graphical_activity: No graphic activity
dotnet_obfuscated: Dotnet program is potentially obfuscated
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
dotnet_suspicious_entrypoint: Dotnet program has suspicious entrypoint
dotnet_downloader_possible_network_problem: Dotnet program possibly has network problem