Managed XDR

1494509775.m487409p695...br-s-22526-w-22883-2-s — malware analysis report

File info

Filename
1494509775.m487409p69517.br540.hostgator.com.br-s-22526-w-22883-2-s
File type
SMTP mail, ASCII text
File size
22 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
3ce2bde000b85fc10761d7540762c7320347e703
SHA256
a70e83a0c558f696714d52635fb5e608011400f4d1ac5bc8bc3ed82a8eb67fb8
MD5
df06f1c268fc7d5605dd6b4bffaa51db

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
dead_host: Connects to IP addresses that do not respond to requests
creates_in_programdata: Creates files in the ProgramData directory