Managed XDR

temp-100-.eml (STRRAT) — malware analysis report

File info

Filename
temp-100-.eml
File type
RFC 822 mail, UTF-8 Unicode text, with CRLF line terminators
File size
642.4 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
b851ca3415ab87d560b21c7a9d443a1daaceaf4f
SHA256
d7709e9576d8e5d35e52875942c6af30985e334bdf58269880eef1bcbea4cff4
MD5
f5bd4a3ce09aff63c23b3f54380bc90b

Malwares

  • STRRAT

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Command and Control

T1102.003 cloud_github: Connects to cloud services of Github (potentially for malicious payload delivery)

Other

yara_rules: Static rules
creates_in_programdata: Creates files in the ProgramData directory

Related reports