Managed XDR

mail.eml — malware analysis report

File info

Filename
mail.eml
File type
RFC 822 mail, ASCII text, with very long lines, with CRLF line terminators
File size
178.3 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
0340ca43117e121906e219dc93cd3fbeb0fb5388
SHA256
f064e3265730ec9391c8299c98e69fc320c0ea635bf9c0b59f8842f139314c5e
MD5
ccd4ad60593935331d1d88e0913998aa

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
pdf_page: Contains only one page
pdf_compressed_stream: Contains an object with compressed stream
get_policy_info: Retrieves information about a Policy object
office_links: Office file contains external links