Managed XDR

20250515.eml — malware analysis report

File info

Filename
20250515.eml
File type
HTML document, ASCII text, with very long lines, with CRLF line terminators
File size
34.5 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
6b67bbeb1d5df24643762904c115e5bb9d9989c1
SHA256
808f72b80d6f2c43329c69b8b806d7f4156c8a6fc877bd8358bd93e6825a8351
MD5
d8b821a4b2cdb8fc2eccb38e8b1f2110

Signatures

Initial Access

T1192 html_urls: HTML-document downloads a file

Execution

T1053.005 persistence_autorun: Makes itself run automatically on Windows startup
T1053.005 creates_tasks: Creates a delayed task using Task Scheduler
T1204.002 mimics_extension: Attempts to mimic the file extension

Persistence

T1053.005 persistence_autorun: Makes itself run automatically on Windows startup
T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1053.005 creates_tasks: Creates a delayed task using Task Scheduler

Privilege Escalation

T1053.005 persistence_autorun: Makes itself run automatically on Windows startup
T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1053.005 creates_tasks: Creates a delayed task using Task Scheduler
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1036 mimics_extension: Attempts to mimic the file extension
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
suricata_alert: Malicious traffic detected
creates_exe: Creates executable files in the file system
dead_host: Connects to IP addresses that do not respond to requests
no_graphical_activity: No graphic activity
creates_in_programdata: Creates files in the ProgramData directory