Managed XDR

sg01317286.eml — malware analysis report

File info

Filename
sg01317286.eml
File type
HTML document, ASCII text, with very long lines, with CRLF line terminators
File size
1.2 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
6ad9b5c4dd586f3984ff4fd1f5660af5c172d7f8
SHA256
7a38361f12c7fcd0003a6238cb9a24d485b077303df67bbb26b3ba18e37dfa24
MD5
81ad20c29353c003ccaa46640a9fbf34

Signatures

Initial Access

T1192 html_urls: HTML-document downloads a file

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497 windows_enumthread: Attempts to enumerate windows using EnumThreadWindows and SendMessage for text obtaining
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497 windows_enumthread: Attempts to enumerate windows using EnumThreadWindows and SendMessage for text obtaining
T1082 windows_enumthread: Attempts to enumerate windows using EnumThreadWindows and SendMessage for text obtaining

Other

yara_rules: Static rules
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card