Managed XDR

fw-re-top-urgent-shipping-documents.msg — malware analysis report

File info

Filename
fw-re-top-urgent-shipping-documents.msg
File type
CDFV2 Microsoft Outlook Message
File size
1.9 MB
First seen
Last seen

Environment

win7/x64 en

Hashes

SHA1
4d399fcf0d934394b946c06ebde9e3b9e1a3f4e5
SHA256
4ab50c62d2e8bc03a1dee6dc040fb57ae2cab4e6d248ae8b46744db19aecab22
MD5
f49a76eeede70fe2066570a27afd6a23

Signatures

Execution

T1059.001 suspicious_powershell: Creates suspicious powershell process
T1059.003 suspicious_batch: Suspicious batch

Privilege Escalation

T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1036 copies_utilities: Copies and runs system utility with different name
T1564.001 stealth_file: Creates hidden or system files
T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antivm_queries_computername: Retrieves the computer name

Other

executes_dropped_exe: Executes dropped exe files
no_graphical_activity: No graphic activity