Managed XDR

4.20240409.20241026.14...t.web.cspambo05.nm.eml — malware analysis report

File info

Filename
4.20240409.20241026.1458.39313.140475199870720.1.spamreport.web.cspambo05.nm.eml
File type
ASCII text, with very long lines, with CRLF line terminators
File size
78 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
d456bced41af65e2fd0187ad3d243bfcf7393568
SHA256
fc2e7dd77c961f2339335a1dfd4b50e7872c18deba49a4042658c1d807a665f9
MD5
03982c6768ae6b24d9a2c2fb68bf44bb

Signatures

Execution

T1059.001 suspicious_powershell: Creates suspicious powershell process
T1059.001 suspicious_process: Spawns a suspicious process

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1518 locates_browser: Attempts to identify where browsers are installed

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
no_graphical_activity: No graphic activity
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object