Managed XDR

spam.txt — malware analysis report

File info

Filename
spam.txt
File type
SMTP mail, ASCII text, with very long lines, with CRLF line terminators
File size
448.1 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
9e17f9a845f2832e54af2774fe735546f90a0369
SHA256
34a668156407344e37c03f118ce8d954272587f83299e929ed13943a08dc5139
MD5
0419e32d910d37b5c970a15c860e3e3d

Signatures

Initial Access

T1192 html_urls: HTML-document downloads a file

Execution

T1059.003 suspicious_cmd: Executes cmd.exe with a suspicious command line
T1059 nsis_suspicious_filenames: Nsis contains files with suspicious names

Persistence

T1574 dropper_dll: Creates DLL, which is then loaded into the process

Privilege Escalation

T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1036.001 invalid_authenticode: Digital signature of the executable file has failed the verification
T1027 suspicious_cmd: Executes cmd.exe with a suspicious command line
T1027.002 nsis_suspicious_filenames: Nsis contains files with suspicious names
T1027.002 nsis_archive: One of the packages is NSIS archive
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1480 system_default_lang_id_present: Checks the system language
T1574 dropper_dll: Creates DLL, which is then loaded into the process

Other

yara_rules: Static rules
creates_many_processes: Spawns a lot of processes (over 70)
no_graphical_activity: No graphic activity
break_limit_exceeded: Warning: function calls limit has been exceeded
creates_exe: Creates executable files in the file system
checktokenmembership: Checks user token with CheckTokenMembership call
pe_overlay: PE file contains overlay
executes_dropped_exe: Executes dropped exe files