Managed XDR

spam-iningvelaspa.eml (Zeus) — malware analysis report

File info

Filename
spam-iningvelaspa.eml
File type
SMTP mail, ASCII text, with CRLF line terminators
File size
956.4 KB
First seen
Last seen

Environment

winxp/x86 en

Hashes

SHA1
65ec7f2cdf1c9ec69d35c03314bfcfe8196d9e84
SHA256
d1eb89e66a56bb4d652e80a250e0576f0977369b4422f628b0e412728e667d06
MD5
7c3728a40bbf7fed39b85a87b3d198a6

Malwares

  • Zeus

Signatures

Initial Access

T1192 html_urls: HTML-document downloads a file

Execution

T1203 office_write_exe: Office document dropped an executable file
T1203 office_exploit_creates_process: The document exhibits suspicious behaviour (spawns a process)
T1559 suspicious_process: Spawns a suspicious process
T1059.003 executes_dropped_cmd: Executes dropped batch files

Persistence

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1574.011 persistence_services: Modifies Services registry key
T1543.003 persistence_services: Modifies Services registry key

Privilege Escalation

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1055 injection_thread: Code injection to a remote process using CreateRemoteThread or NtQueueApcThread
T1055.002 inject_write_pe: Writes PE file to another process's memory
T1055.012 injection_runpe: Injects code into another process
T1574.011 persistence_services: Modifies Services registry key
T1543.003 persistence_services: Modifies Services registry key
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1055 injection_thread: Code injection to a remote process using CreateRemoteThread or NtQueueApcThread
T1055.002 inject_write_pe: Writes PE file to another process's memory
T1055.012 injection_runpe: Injects code into another process
T1562.004 bypass_firewall: Changes local firewall configuration and policies
T1027.002 unnamed_memory_regions_contains_pe: One or several unnamed memory regions are PE files
T1562.001 disables_security: Disables Windows Security options
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1070.004 self_delete_bat: Creates and runs a .bat file that removes the original binary file
T1574.011 persistence_services: Modifies Services registry key
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1552 infostealer_mail: Collects personal data from local email clients

Discovery

T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Collection

T1114 infostealer_mail: Collects personal data from local email clients

Other

yara_rules: Static rules
executes_dropped_exe: Executes dropped exe files
nemty_mutex: Nemty is detected: mutex
banker_zeus_mutex: Banking Trojan indicators detected (mutexes)
banker_zeus_p2p: Zeus P2P banking Trojan indicators detected
opens_document: Opens office documents
creates_exe: Creates executable files in the file system
creates_doc: Creates (office) documents in the file system
creates_in_programdata: Creates files in the ProgramData directory
open_winlogon_process: Trying to open winlogon process

Related reports