Managed XDR

20250722_fp_100_280.eml — malware analysis report

File info

Filename
20250722_fp_100_280.eml
File type
UTF-8 Unicode text
File size
1.4 MB
First seen
Last seen

Environment

w10/x86 en

Hashes

SHA1
0e6dc941760be67f4603ce6f230d1e081c1ab2e2
SHA256
4201a6ef77ba462d9b1508bf6335ba2906e8e25ec00b36af220359043651023b
MD5
1b158ea76b6e4b81f80b5bcd49672136

Signatures

Privilege Escalation

T1055.002 inject_write_pe: Writes PE file to another process's memory
T1055.012 injection_runpe: Injects code into another process
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1055.002 inject_write_pe: Writes PE file to another process's memory
T1055.012 injection_runpe: Injects code into another process
T1027.002 unnamed_memory_regions_contains_pe: One or several unnamed memory regions are PE files
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1027.002 packer_vb: The executable file is packed using VB
T1497.001 antivm_queries_computername: Retrieves the computer name
T1480 system_default_lang_id_present: Checks the system language
T1070 stealth_window: A process created a hidden window

Discovery

T1497.001 antivm_queries_computername: Retrieves the computer name

Other

yara_rules: Static rules
steganographic_png: Possible malicious steganographic PNG
creates_in_windows: Creates files in the Windows directory
creates_exe: Creates executable files in the file system
create_process_failed: Could not start the process
unexpected_exception: Unexpected exception
no_graphical_activity: No graphic activity
has_pdb: This executable file has a PDB path
creates_suspended_process: Creates suspended process
suspicious_network_port: Performs TCP or UDP request to non-standard port
test_check_service: Starts services
suricata_alert: Malicious traffic detected
dotnet_downloader_possible_network_problem: Dotnet program possibly has network problem
dotnet_suspicious_module_name: Dotnet program has suspicious module name
Managed XDR