Managed XDR

external-pague-a-tiemp...entrales-de-riesgo.msg — malware analysis report

File info

Filename
external-pague-a-tiempo-evite-ser-reportado-en-las-centrales-de-riesgo.msg
File type
CDFV2 Microsoft Outlook Message
File size
1.4 MB
First seen
Last seen

Environment

w10/x86 en

Hashes

SHA1
28e40b8e87d72de88c3bd051b003d209a4811a5b
SHA256
214eef191b2a1d39a2b1abf9b87e9d24fc6ca3c5f65e39e85c4669d48c94e53f
MD5
fa1bc0136bfc054a2d03fe63449bde91

Signatures

Persistence

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup

Privilege Escalation

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1497.001 antivm_disk_size: Checks the amount of free disk space
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antivm_disk_size: Checks the amount of free disk space
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1497.001 antivm_queries_computername: Retrieves the computer name

Exfiltration

T1022 encrypts_pc_info: Collects and encrypts information about the computer (possibly for exfiltration)

Other

creates_exe: Creates executable files in the file system
pe_in_bcryptdecrypt: PE found in BCryptDecrypt function
copies_self: Creates a copy of itself
dead_host: Connects to IP addresses that do not respond to requests
no_graphical_activity: No graphic activity
dotnet_suspicious_resources_names: Dotnet program has suspicious resources names
checktokenmembership: Checks user token with CheckTokenMembership call