Managed XDR

3fdf546d47f75d694c8924e1584ed0da.eml — malware analysis report

File info

Filename
3fdf546d47f75d694c8924e1584ed0da.eml
File type
RFC 822 mail, UTF-8 Unicode text, with CRLF line terminators
File size
1.6 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
3111c77a2f793e01776c1403dc1cc91b90636f4e
SHA256
7d243d6feabae95667f23aa90b97d3620c386fd189345c8134824b2ba7df62eb
MD5
3fdf546d47f75d694c8924e1584ed0da

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
require_administrator: Requests administrator privileges
message_box: Displays a message
pe_overlay: PE file contains overlay