Managed XDR

notificacion_urgente-yuleima.eml — malware analysis report

File info

Filename
notificacion_urgente-yuleima.eml
File type
RFC 822 mail, ASCII text, with CRLF line terminators
File size
10.2 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
d4cf3eb5e3df830a06e0fed89e31897623ef92d3
SHA256
20a8307648ef17c87ba8e7fbf679acde9d76f9167d312ce072303bf535613c5c
MD5
e567a2a7c5786375f50398fc9c7314ec

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
creates_suspended_process: Creates suspended process
origin_langid: Unconventional language of the executable file