Managed XDR

608023104.eml — malware analysis report

File info

Filename
608023104.eml
File type
SMTP mail, ASCII text, with very long lines, with CRLF line terminators
File size
302.7 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
ba84a429e583157480d2fe3076c3e0e7d0ac999e
SHA256
29c32e397eb7d1c7ef0cca7948c3c1d621bb6383290350dc42818b8e1ebeaa7a
MD5
681c08f31ddea1e3b09706aa144ed6b9

Signatures

Execution

T1204 suspicious_lnk: LNK file with suspicious content
T1059.001 suspicious_process: Spawns a suspicious process

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1518 locates_browser: Attempts to identify where browsers are installed
T1135 server_share_info: Retrieves information about each shared resource on a server

Command and Control

T1071.001 network_http: Performs HTTP requests
T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp

Other

yara_rules: Static rules
runs_utility_without_cmdline: Runs system utility without arguments (non-typical usage)
unexpected_exception: Unexpected exception
create_rpc_bindings: Creates RPC connection
creates_suspended_process: Creates suspended process
static_compression_ratio: Very high compression ratio of a file
get_policy_info: Retrieves information about a Policy object
checktokenmembership: Checks user token with CheckTokenMembership call