Managed XDR

vade_clean_varist_posi...ata_2nd_batch_1973.eml — malware analysis report

File info

Filename
vade_clean_varist_positive_data_2nd_batch_1973.eml
File type
ASCII text
File size
29.1 KB
First seen
Last seen

Environment

w10/x86 en

Hashes

SHA1
cda244d92b2728cb7f5b0a684fd324ff4f230123
SHA256
cb029d6022b522581f283220a6ea6628d10c9c2281da32d1354289e74aafba2e
MD5
d3bfb9362a8de24a92df1c8a4f7def9f

Signatures

Privilege Escalation

T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Command and Control

T1102.003 cloud_discord: Connects to cloud services of Discord (potentially for malicious payload delivery)

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
dotnet_obfuscated: Dotnet program is potentially obfuscated
get_policy_info: Retrieves information about a Policy object
checktokenmembership: Checks user token with CheckTokenMembership call
suricata_alert: Malicious traffic detected
dotnet_downloader_possible_network_problem: Dotnet program possibly has network problem
dotnet_suspicious_module_name: Dotnet program has suspicious module name