Managed XDR

c-users-user-appdata-l...a41cfc50-zqa-email.eml — malware analysis report

File info

Filename
c-users-user-appdata-local-temp-gyoqztv4.3rx-sendmail-messages_package-09.x64_bind_inject_notepad-.rar-d1cccbeda41cfc50-zqa-email.eml
File type
RFC 822 mail, ASCII text, with CRLF line terminators
File size
10.9 KB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
39c0ad3d573e31ed069a3d3635c9ae16bc1674d5
SHA256
145c59201ef7f6f3b68c76f44a4f82f806b171ee1a65e2bf5d21e74256bff8dd
MD5
9b82af36e1147d178b488757d31c439e

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
has_pdb: This executable file has a PDB path
creates_suspended_process: Creates suspended process
test_check_service: Starts services