Managed XDR

2755b9e1-8ba0-3f04-9d07-c61107164619.eml — malware analysis report

File info

Filename
2755b9e1-8ba0-3f04-9d07-c61107164619.eml
File type
RFC 822 mail, ASCII text, with CRLF line terminators
File size
338.5 KB
First seen
Last seen

Environment

w10/x86 en

Hashes

SHA1
1e9f43b0f5831dd3a0d25f1d3891bb1ec08517e5
SHA256
cae79d39cbfb00d095815642c630a56da2388ac6dd2912ddde58067ce2e26078
MD5
255b10225b0f7322ca7e399d99c54224

Signatures

Privilege Escalation

T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
get_policy_info: Retrieves information about a Policy object
checktokenmembership: Checks user token with CheckTokenMembership call
dotnet_suspicious_entrypoint: Dotnet program has suspicious entrypoint
dotnet_downloader_possible_network_problem: Dotnet program possibly has network problem
dotnet_suspicious_module_name: Dotnet program has suspicious module name