Managed XDR

37a2caa8fe1ac32ebfc505cb87dff0a5.eml — malware analysis report

File info

Filename
37a2caa8fe1ac32ebfc505cb87dff0a5.eml
File type
RFC 822 mail, ASCII text, with very long lines, with CRLF, LF line terminators
File size
468.6 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
df3246a07770822a94ada964bd81cac437329f08
SHA256
37ec3283f015f38a34c708c0cdf04f37607f0df4fa8fb14357f752b5aa78fc1a
MD5
ed764f32d661a7005b0574b21d99144e

Signatures

Execution

T1203 office_write_exe: Office document dropped an executable file
T1559 suspicious_process: Spawns a suspicious process
T1064 office_macros_strings: Feature lines found in document macro
T1204.002 office_vb_load: Microsoft Office is loading VB DLL files (macros usage indicator)

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027 office_macros_entropy: The document contains a macro with high entropy (a possible sign of obfuscation)
T1027 office_macros_hex_strings: Lines in hex found in document macro
T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1497 windows_enumthread: Attempts to enumerate windows using EnumThreadWindows and SendMessage for text obtaining
T1497.001 antivm_queries_computername: Retrieves the computer name
T1497.002 async_mouse: Watches for mouse clicks using GetAsyncKeyState to detect human activity
T1064 office_macros_strings: Feature lines found in document macro
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files
T1056.001 infostealer_keylogger: Keylogger (intercepts keystrokes)

Discovery

T1057 process_interest: Enumerates processes
T1049 list_ts_rdp_sessions: Lists ts/rdp sessions
T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1497 windows_enumthread: Attempts to enumerate windows using EnumThreadWindows and SendMessage for text obtaining
T1497.001 antivm_queries_computername: Retrieves the computer name
T1497.002 async_mouse: Watches for mouse clicks using GetAsyncKeyState to detect human activity
T1083 checks_recent_files: Attempt to check recently opened files through registry
T1082 windows_enumthread: Attempts to enumerate windows using EnumThreadWindows and SendMessage for text obtaining

Collection

T1056.001 infostealer_keylogger: Keylogger (intercepts keystrokes)

Other

yara_rules: Static rules
executes_dropped_exe: Executes dropped exe files
creates_exe: Creates executable files in the file system
create_rpc_bindings: Creates RPC connection
break_limit_exceeded: Warning: function calls limit has been exceeded
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card
open_winlogon_process: Trying to open winlogon process