Managed XDR

request-for-quotation.eml — malware analysis report

File info

Filename
request-for-quotation.eml
File type
HTML document, ASCII text, with very long lines, with CRLF line terminators
File size
17 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
f637825f76d298f857b825072fd3a193ba556b72
SHA256
85ff369a5dd9f3f91c90c7aecca30d48c92a05c6cf66a40678fee9755492144a
MD5
756fa65ceeab330d5d406af41ac51d61

Signatures

Execution

T1059.001 suspicious_powershell: Creates suspicious powershell process
T1204.002 mimics_extension: Attempts to mimic the file extension
T1059.001 suspicious_process: Spawns a suspicious process

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1036 mimics_extension: Attempts to mimic the file extension
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1070 stealth_window: A process created a hidden window
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1552 cookie_files: Accesses cookie files
T1555.003 cookie_files: Accesses cookie files

Discovery

T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Command and Control

T1071.001 network_cnc_http: Suspicious HTTP traffic
T1071.001 network_http: Performs HTTP requests

Other

yara_rules: Static rules
network_ftp: Performs FTP requests
no_graphical_activity: No graphic activity
get_policy_info: Retrieves information about a Policy object