Managed XDR

03b1ade76a53ee1c232f84...aeda1ff399586228b4.eml — malware analysis report

File info

Filename
03b1ade76a53ee1c232f84b3898000fcc8bc4cbf5be805aeda1ff399586228b4.eml
File type
HTML document, ASCII text, with very long lines, with CRLF line terminators
File size
186.7 KB
First seen
Last seen

Environment

w10/x86 en

Hashes

SHA1
4cd397ff0520d6dfdcfddac6944ff1d02998a12b
SHA256
e819ba815090ed3ae48819b0070be3833f72f012556a1bbf7858db718a1f8d65
MD5
8de90edbc4e8b4b9d513859df5b14827

Signatures

Privilege Escalation

T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.001 antivm_network_adapters: Checks NIC addresses
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antivm_network_adapters: Checks NIC addresses
T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
get_policy_info: Retrieves information about a Policy object
checktokenmembership: Checks user token with CheckTokenMembership call
dotnet_downloader_possible_network_problem: Dotnet program possibly has network problem
dotnet_suspicious_module_name: Dotnet program has suspicious module name