Managed XDR

b67868a0a930f31b523eb82d4dde0f83.bin — malware analysis report

File info

Filename
b67868a0a930f31b523eb82d4dde0f83.bin
File type
RFC 822 mail, ASCII text, with very long lines, with CRLF line terminators
File size
23.2 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
bfadf05826ede7bc68461dda78248224a488dc02
SHA256
fb2ce8dd0b05ab92d20106c64c34a24b80586fc7dd247a942aff0371470241b0
MD5
b67868a0a930f31b523eb82d4dde0f83

Signatures

Execution

T1204.002 mimics_extension: Attempts to mimic the file extension

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1036 mimics_extension: Attempts to mimic the file extension
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files

Command and Control

T1071.001 wininet_openurl: Performs HTTP/HTTPS-requests using InternetOpenUrl

Other

yara_rules: Static rules
dead_host: Connects to IP addresses that do not respond to requests
no_graphical_activity: No graphic activity
create_rpc_bindings: Creates RPC connection
message_box: Displays a message
get_policy_info: Retrieves information about a Policy object