Managed XDR

vade_clean_varist_posi...data_2nd_batch_630.eml — malware analysis report

File info

Filename
vade_clean_varist_positive_data_2nd_batch_630.eml
File type
HTML document, ASCII text, with very long lines
File size
1.2 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
d244f57ca92b4dc4c829604a1f8ecb3f77a2fddf
SHA256
0564737fc7e9b2d0cd8e32081fa3289f406d42f5d3fbe1528f1da834b8344aa4
MD5
1f358503b9b06fcf7e0bfa25447b6f2e

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1036 copies_utilities: Copies and runs system utility with different name
T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antivm_queries_computername: Retrieves the computer name

Command and Control

T1105 lolbin_extrac32: Download or Copy file with Extrac32

Other

executes_dropped_exe: Executes dropped exe files
creates_exe: Creates executable files in the file system
creates_in_windows: Creates files in the Windows directory
unexpected_exception: Unexpected exception
create_rpc_bindings: Creates RPC connection
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object
checktokenmembership: Checks user token with CheckTokenMembership call
yara_rules: Static rules