Managed XDR

swedbank-2025-04-08-2016.eml — malware analysis report

File info

Filename
swedbank-2025-04-08-2016.eml
File type
ASCII text, with CRLF line terminators
File size
26.6 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
bcb5510b7a8bacd3ce2a1a5daa83149796921e6c
SHA256
82a71d82509198e79f801a6053f9ccfe4b2edcc3bb751fed0a12f8ec55e3d9ce
MD5
9f1e218d8676d9e9a4766e2e9d04c3d2

Signatures

Execution

T1204.002 mimics_extension: Attempts to mimic the file extension

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1036 mimics_extension: Attempts to mimic the file extension
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Command and Control

T1071.001 network_http: Performs HTTP requests

Other

networkdyndns_checkip: Connects to a Dynamic DNS domain
yara_rules: Static rules
ip_domains: Identifies an IP address using external resources
creates_in_programdata: Creates files in the ProgramData directory