Managed XDR

temp-11-.eml (Remcos) — malware analysis report

File info

Filename
temp-11-.eml
File type
RFC 822 mail, ASCII text, with CRLF line terminators
File size
768.3 KB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
2fdd573dfb6d9fde7623b12fae23c4346dd84633
SHA256
baa8c58c7635df740651d03a003c3b8047d70c7f014e7cf1dc6ff7dc5f78d56c
MD5
cbe564422828e036e48d91a51f1fb8df

Malwares

  • Remcos

Signatures

Execution

T1059.001 suspicious_powershell: Creates suspicious powershell process
T1059 powershell_cmd_longcommandline: Suspiciously long commandline
T1059.001 suspicious_process: Spawns a suspicious process
T1059.003 suspicious_batch: Suspicious batch

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1562 dep_disable: Disables DEP
T1497.003 antisandbox_idletime: Detects Windows Idle Time to determine the uptime
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1027 many_env_vars: An extensive number of environment variables has been created (possible sign of obfuscation)

Discovery

T1497.003 antisandbox_idletime: Detects Windows Idle Time to determine the uptime
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1518 locates_browser: Attempts to identify where browsers are installed

Other

yara_rules: Static rules
ce_info: Remcos Configuration Data found
creates_exe: Creates executable files in the file system
ps_ep_changed: Changes Powershell execution policy
creates_suspended_process: Creates suspended process
creates_in_programdata: Creates files in the ProgramData directory
test_check_service: Starts services

Related reports