Managed XDR

virussample1.eml — malware analysis report

File info

Filename
virussample1.eml
File type
RFC 822 mail, ASCII text, with very long lines, with CRLF line terminators
File size
465.2 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
ddd3dbc6af43bcca63e467c23172208844183bef
SHA256
400ee1be11186e745b13939f4228fc81cec50af659c93ada36843f8f17ddff06
MD5
999e6f48e7325f0eee3ec2855284afe8

Signatures

Execution

T1059.001 suspicious_powershell: Creates suspicious powershell process
T1059 powershell_cmd_longcommandline: Suspiciously long commandline
T1059.007 bad_js: Suspicious Javascript file
T1059.001 suspicious_process: Spawns a suspicious process
T1059.003 suspicious_batch: Suspicious batch

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1070 stealth_window: A process created a hidden window
T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1518 locates_browser: Attempts to identify where browsers are installed
T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Other

creates_in_windows: Creates files in the Windows directory
creates_exe: Creates executable files in the file system
no_graphical_activity: No graphic activity
break_limit_exceeded: Warning: function calls limit has been exceeded
get_policy_info: Retrieves information about a Policy object
checktokenmembership: Checks user token with CheckTokenMembership call
yara_rules: Static rules