Managed XDR

4e569a8038624f132753e0...d76032801a0cef2f92.eml — malware analysis report

File info

Filename
4e569a8038624f132753e0d76032801a0cef2f92.eml
File type
SMTP mail, ASCII text, with very long lines, with CRLF line terminators
File size
568.8 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
4e569a8038624f132753e0d76032801a0cef2f92
SHA256
422460ee17425307da6a015e544ae4dd5dbacc67edb67946fb8db5fbe5b3c595
MD5
82bdcc51adbc4957d81cd5da4a7d5e1e

Signatures

Execution

T1106 susp_callbacks: Suspicious usage of some WinAPI with callbacks

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 unnamed_memory_regions_contains_pe: One or several unnamed memory regions are PE files
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files

Discovery

T1518 locates_browser: Attempts to identify where browsers are installed

Command and Control

T1102.003 cloud_onedrive: Connects to cloud services of Onedrive (potentially for malicious payload delivery)
T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp

Other

yara_rules: Static rules
dbatloader_behaviour: DBatLoader/ModiLoader behaviour
process_crashed: One of the processes has failed
no_graphical_activity: No graphic activity
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services