Managed XDR

af9bfbb464.eml — malware analysis report

File info

Filename
af9bfbb464.eml
File type
RFC 822 mail, ASCII text, with very long lines
File size
22.5 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
2c133d0b1b8327719f53fc3ffa57497ebb274996
SHA256
db16a41014fa68812020b968f23d086583a14e4e737bc3c41c0f81ff51955eb1
MD5
9345706aeb0baef05a00c5addda9eb98

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Command and Control

T1071.001 network_http: Performs HTTP requests

Other

networkdyndns_checkip: Connects to a Dynamic DNS domain
yara_rules: Static rules
ip_domains: Identifies an IP address using external resources
creates_in_programdata: Creates files in the ProgramData directory