Managed XDR

generated_email.eml — malware analysis report

File info

Filename
generated_email.eml
File type
news or mail, ASCII text, with CRLF line terminators
File size
2.9 MB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
e5bab00a2f43d47176290bde0ddc8e3fb7313f9f
SHA256
bf70ffc9a2bd72937c89f869cfbe74348f06dc1bb85cadd1ffe055e93c48cf8b
MD5
f254728d170311fc629be64cf36b34a4

Signatures

Persistence

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1574 dropper_dll: Creates DLL, which is then loaded into the process

Privilege Escalation

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_polymorphic: Creates a modified copy of itself
T1497 evasion_diskenum: Sandbox evasion using enumeration of partitions
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497 evasion_diskenum: Sandbox evasion using enumeration of partitions
T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Command and Control

T1071.003 network_smtp: Performs SMTP requests, possibly sends SPAM messages

Other

yara_rules: Static rules
creates_in_windows: Creates files in the Windows directory
network_bind: Starts servers listening at 0.0.0.0:3127, 0.0.0.0:3128, 0.0.0.0:3129, 0.0.0.0:3130, 0.0.0.0:3131, 0.0.0.0:3132, 0.0.0.0:3133, 0.0.0.0:3134, 0.0.0.0:3135, 0.0.0.0:3136, 0.0.0.0:3137, 0.0.0.0:3138, 0.0.0.0:3139, 0.0.0.0:3140, 0.0.0.0:3141, 0.0.0.0:3142, 0.0.0.0:3143, 0.0.0.0:3144, 0.0.0.0:3145, 0.0.0.0:3146, 0.0.0.0:3147, 0.0.0.0:3148, 0.0.0.0:3149, 0.0.0.0:3150, 0.0.0.0:3151, 0.0.0.0:3152, 0.0.0.0:3153, 0.0.0.0:3154, 0.0.0.0:3155, 0.0.0.0:3156, 0.0.0.0:3157, 0.0.0.0:3158, 0.0.0.0:3159, 0.0.0.0:3160, 0.0.0.0:3161, 0.0.0.0:3162, 0.0.0.0:3163, 0.0.0.0:3164, 0.0.0.0:3165, 0.0.0.0:3166, 0.0.0.0:3167, 0.0.0.0:3168, 0.0.0.0:3169, 0.0.0.0:3170, 0.0.0.0:3171, 0.0.0.0:3172, 0.0.0.0:3173, 0.0.0.0:3174, 0.0.0.0:3175, 0.0.0.0:3176, 0.0.0.0:3177, 0.0.0.0:3178, 0.0.0.0:3179, 0.0.0.0:3180, 0.0.0.0:3181, 0.0.0.0:3182, 0.0.0.0:3183, 0.0.0.0:3184, 0.0.0.0:3185, 0.0.0.0:3186, 0.0.0.0:3187, 0.0.0.0:3188, 0.0.0.0:3189, 0.0.0.0:3190, 0.0.0.0:3191, 0.0.0.0:3192, 0.0.0.0:3193, 0.0.0.0:3194, 0.0.0.0:3195, 0.0.0.0:3196, 0.0.0.0:3197, 0.0.0.0:3198, 0.0.0.0:3199
creates_exe: Creates executable files in the file system
network_ftp: Performs FTP requests
has_pdb: This executable file has a PDB path
creates_suspended_process: Creates suspended process
break_limit_exceeded: Warning: function calls limit has been exceeded
test_check_service: Starts services
copies_self: Creates a copy of itself
writes_data: Writes big amount of data to disk