Managed XDR

mail.eml — malware analysis report

File info

Filename
mail.eml
File type
news or mail, ASCII text, with very long lines, with CRLF, LF line terminators
File size
18.3 KB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
5b5b1166af8b8a143fb9fe8fd816643a79dfc3f3
SHA256
0262bb10c5af8c79af39b38c9f9630cd0e94a5040947a25c07a47597c0d86800
MD5
4795f270f8bb188e5dba90017619f17e

Signatures

Initial Access

T1192 html_urls: HTML-document downloads a file

Execution

T1204.002 office_com_load: Microsoft Office loads COM DLL files (indicator of COM usage in macros)

Privilege Escalation

T1055 injection_failed: The attempt to inject into a process has failed

Defense Evasion

T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization
T1055 injection_failed: The attempt to inject into a process has failed

Credential Access

T1555.004 windows_credential_manager: Acquire credentials from the Windows Credential Manager

Discovery

T1518 locates_browser: Attempts to identify where browsers are installed
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization

Command and Control

T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp
T1071.001 wininet_https: Performs HTTP/HTTPS requests using WinInet

Other

suricata_alert: Malicious traffic detected
network_bind: Starts servers listening at None
suspicious_network_port: Performs TCP or UDP request to non-standard port
test_check_service: Starts services