Managed XDR

vade_clean_varist_posi...ata_2nd_batch_1677.eml — malware analysis report

File info

Filename
vade_clean_varist_positive_data_2nd_batch_1677.eml
File type
HTML document, ASCII text, with CRLF, LF line terminators
File size
19.7 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
6f7a6475597332a1e9ab5236a233094d8b7ce5a1
SHA256
ce64ca90658284f1cf0f3c78c695c773a6003b9afa3f39b42030b06b9abd3318
MD5
9d0941d79dac4315bef2d242a8e263f1

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_vb: The executable file is packed using VB
T1480 system_default_lang_id_present: Checks the system language
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
opens_document: Opens office documents
creates_exe: Creates executable files in the file system
create_process_failed: Could not start the process
creates_doc: Creates (office) documents in the file system
get_policy_info: Retrieves information about a Policy object