Managed XDR

quotation.eml — malware analysis report

File info

Filename
quotation.eml
File type
HTML document, ASCII text, with very long lines, with CRLF line terminators
File size
1.3 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
5a604b2fb20f9bc4715b29e34f1f46756d88d7bc
SHA256
de9df675bd27c39c69a77536d57655f5419b2373aa2038d87b1d307f1c1de281
MD5
c14c2033cb8f6980329c58a0d5b11ca5

Signatures

Execution

T1059.001 suspicious_powershell: Creates suspicious powershell process

Privilege Escalation

T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1055 injection_failed: The attempt to inject into a process has failed

Defense Evasion

T1036.001 invalid_authenticode: Digital signature of the executable file has failed the verification
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1562.001 windows_defender_add_exclusion: Adds a path to Microsoft Defender exclusion list
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1055 injection_failed: The attempt to inject into a process has failed
T1070 stealth_window: A process created a hidden window

Discovery

T1518 locates_browser: Attempts to identify where browsers are installed

Other

steganographic_png: Possible malicious steganographic PNG
unpacker_wrong_base: Possibly, an error occured in the file unpacker
no_graphical_activity: No graphic activity
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object
checktokenmembership: Checks user token with CheckTokenMembership call
pe_overlay: PE file contains overlay
yara_rules: Static rules
dotnet_suspicious_module_name: Dotnet program has suspicious module name