Managed XDR

transaccion-aprobada-p...les-interbancarios.eml — malware analysis report

File info

Filename
transaccion-aprobada-pagos-pse-a-traves-de-portales-interbancarios.eml
File type
RFC 822 mail, ASCII text, with CRLF line terminators
File size
14.8 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
5a9fa4fb421275f3fa397f33ca1d8ec0e5b09fb6
SHA256
86db7d40387c4bd95a9a7dbab05dd0a1240d5c5e5760b610cd25b9f74c7f459e
MD5
42de1aeda39094fa4c68d813f4d6149d

Signatures

Execution

T1059.001 suspicious_powershell: Creates suspicious powershell process
T1059.001 suspicious_process: Spawns a suspicious process

Persistence

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup

Privilege Escalation

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1518 locates_browser: Attempts to identify where browsers are installed

Command and Control

T1102.003 references_google: Contains links to cloud services of Google (potentially for malicious payload delivery)

Other

modifies_certs: Attempts to generate or modify system certificates
creates_exe: Creates executable files in the file system
checktokenmembership: Checks user token with CheckTokenMembership call