Managed XDR

1102039.eml (CloudEyE) — malware analysis report

File info

Filename
1102039.eml
File type
SMTP mail, ASCII text, with very long lines, with CRLF line terminators
File size
727.4 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
87b888e01c4721d9a4d09907ab8bd34d2504b181
SHA256
00bc635897db0a78d3673fa1bef5d65f9246ea48d143691c1cd67cee9703c5b5
MD5
ff2134a8262b203c97cb8769fdad6761

Malwares

  • CloudEyE

Signatures

Execution

T1204.002 mimics_extension: Attempts to mimic the file extension
T1059 nsis_suspicious_filenames: Nsis contains files with suspicious names
T1106 susp_callbacks: Suspicious usage of some WinAPI with callbacks

Persistence

T1574 dropper_dll: Creates DLL, which is then loaded into the process

Privilege Escalation

T1055.012 injection_runpe: Injects code into another process
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1574 dropper_dll: Creates DLL, which is then loaded into the process

Defense Evasion

T1055.012 injection_runpe: Injects code into another process
T1497 antidbg_setinformationthread: Attempts to evade debugger using NtSetInformationThread
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1036 mimics_extension: Attempts to mimic the file extension
T1027.002 nsis_archive: One of the packages is NSIS archive
T1027.002 nsis_suspicious_filenames: Nsis contains files with suspicious names
T1480 system_default_lang_id_present: Checks the system language
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497 antidbg_setinformationthread: Attempts to evade debugger using NtSetInformationThread

Other

yara_rules: Static rules
unnamed_region_exception_handler: Creates an exception handler in an unnamed region
process_crashed: One of the processes has failed
unexpected_exception: Unexpected exception
no_graphical_activity: No graphic activity
creates_suspended_process: Creates suspended process
creates_exe: Creates executable files in the file system
test_check_service: Starts services
checktokenmembership: Checks user token with CheckTokenMembership call
pe_overlay: PE file contains overlay
nsis_mouse_movement: NSIS tracks mouse movement

Related reports