Managed XDR

bastian455_-518f16054b...94efa4a712f7a3958a.eml — malware analysis report

File info

Filename
bastian455_-518f16054bc6e1b1953589344280c33ecaf35357f0c0fd94efa4a712f7a3958a.eml
File type
HTML document, ASCII text, with very long lines, with CRLF line terminators
File size
2.2 MB
First seen
Last seen

Environment

w10/x86 en

Hashes

SHA1
ee292b116a5cc149e00decbe69e3189aeb753228
SHA256
518f16054bc6e1b1953589344280c33ecaf35357f0c0fd94efa4a712f7a3958a
MD5
a3d776065e32a1776a23a8f7392863b8

Signatures

Privilege Escalation

T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1036.001 invalid_authenticode: Digital signature of the executable file has failed the verification
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
pe_in_bcryptdecrypt: PE found in BCryptDecrypt function
no_graphical_activity: No graphic activity
dotnet_suspicious_resources_names: Dotnet program has suspicious resources names
dotnet_obfuscated: Dotnet program is potentially obfuscated
static_compression_ratio: Very high compression ratio of a file
pe_overlay: PE file contains overlay
static_big_overlay: Executable file contains an enormously big overlay
dotnet_suspicious_module_name: Dotnet program has suspicious module name