Managed XDR

vade_clean_varist_posi..._data_2nd_batch_47.eml — malware analysis report

File info

Filename
vade_clean_varist_positive_data_2nd_batch_47.eml
File type
HTML document, ASCII text
File size
5 MB
First seen
Last seen

Environment

win7/x64 en

Hashes

SHA1
f2ff693b9b6d8e309ac56b94d311a7f28c05d0c2
SHA256
00eb638d4b60d551ce8ab24e24d292a4904ef5027d6aabe8bf1f54496c42b045
MD5
ebc2fbddb195ac4ebed392c5398a0f0f

Signatures

Initial Access

T1192 html_urls: HTML-document downloads a file

Execution

T1204.002 mimics_extension: Attempts to mimic the file extension

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1036 mimics_extension: Attempts to mimic the file extension
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
valid_authenticode: The digital signature has been verified
has_pdb: This executable file has a PDB path
pe_overlay: PE file contains overlay