Managed XDR

4.20251030.20260518.15....cvspambo001.wmail.eml — malware analysis report

File info

Filename
4.20251030.20260518.15179.22476.139786249565952.1.spamreport.web.cvspambo001.wmail.eml
File type
HTML document, ASCII text, with CRLF line terminators
File size
3.2 MB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
c06c6ca1b4918fd5eb0e7b71dac19a4fd2452e90
SHA256
5517c2bb2a96b04dee4d369c964fc704adbc7b14696bf003f4fbb3bf335ce02a
MD5
849b6b5420866d4078d7314d4542547d

Signatures

Persistence

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1574 dropper_dll: Creates DLL, which is then loaded into the process

Privilege Escalation

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 opens_process_token: Opens the access token associated with a process
T1055 injection_failed: The attempt to inject into a process has failed

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1027.004 compiles_code: Compiles VB.NET code
T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 opens_process_token: Opens the access token associated with a process
T1055 injection_failed: The attempt to inject into a process has failed

Other

runs_utility_without_cmdline: Runs system utility without arguments (non-typical usage)
copies_self: Creates a copy of itself
creates_exe: Creates executable files in the file system
create_process_failed: Could not start the process
suspicious_process: Spawns a suspicious process
valid_authenticode: The digital signature has been verified
has_pdb: This executable file has a PDB path
creates_suspended_process: Creates suspended process
test_check_service: Starts services
pe_overlay: PE file contains overlay