Managed XDR

attached-3-.eml — malware analysis report

File info

Filename
attached-3-.eml
File type
RFC 822 mail, ASCII text
File size
17.7 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
ba7dbad85d87a8ec52f7e2fce095e870d72dadb1
SHA256
b5c70af49b6d9d6ee0de3fffd5459117ee98ea2617ed042cd989b290242ebec0
MD5
538f22ac36c61a04a511eefb13edfbfc

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1036 copies_utilities: Copies system utility with different name
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1083 crawls_directories: Opens a huge number of directories all over disk C: (possibly, searches for sensitive data)
T1518 locates_browser: Attempts to identify where browsers are installed

Collection

T1560.001 archive_via_utility: Detected archiving data via utility

Command and Control

T1105 lolbin_extrac32: Download or Copy file with Extrac32

Other

yara_rules: Static rules
creates_exe: Creates executable files in the file system
create_process_failed: Could not start the process
no_graphical_activity: No graphic activity
checktokenmembership: Checks user token with CheckTokenMembership call