Managed XDR

2adcb1eb171232c8149033...86f1c14d86543a3f27.eml (TeslaCrypt) — malware analysis report

File info

Filename
2adcb1eb171232c8149033313b1d145ed6c5c021ce3e7a86f1c14d86543a3f27.eml
File type
ASCII text, with very long lines, with CRLF line terminators
File size
151.6 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
3f992df8744f0d4ddda87ef6148ba99dbc9eba85
SHA256
71f2cf7d94a25911a3ba54e1aea380c80454e8eead5d65cd45e85bcdaf34de47
MD5
5f56b6797b22cc6afc3cf7979cd9f12d

Malwares

  • TeslaCrypt

Signatures

Initial Access

T1192 html_urls: HTML-document downloads a file

Execution

T1059.001 suspicious_powershell: Creates suspicious powershell process
T1059 powershell_cmd_longcommandline: Suspiciously long commandline
T1059.001 suspicious_process: Spawns a suspicious process
T1059.003 suspicious_process: Spawns a suspicious process
T1059.003 executes_dropped_cmd: Executes dropped batch files
T1559.001 com_exec: Execution of Win32_Process.Create COM Method
T1059.003 suspicious_batch: Suspicious batch

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497 debugs_self: Creates a process and debugs it
T1027 many_env_vars: An extensive number of environment variables has been created (possible sign of obfuscation)
T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1497.002 async_mouse: Watches for mouse clicks using GetAsyncKeyState to detect human activity
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497 debugs_self: Creates a process and debugs it
T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1497.002 async_mouse: Watches for mouse clicks using GetAsyncKeyState to detect human activity
T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Other

yara_rules: Static rules
creates_exe: Creates executable files in the file system
pdf_compressed_stream: Contains an object with compressed stream
get_policy_info: Retrieves information about a Policy object
office_links: Office file contains external links
checktokenmembership: Checks user token with CheckTokenMembership call

Related reports

Managed XDR