Managed XDR

4.20240409.20241026.36....cvspambo002.wmail.eml — malware analysis report

File info

Filename
4.20240409.20241026.361796.28416.139859612518144.1.spamreport.web.cvspambo002.wmail.eml
File type
UTF-8 Unicode text, with CRLF line terminators
File size
160.4 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
30865723f789d542b69bf59da02d8b6bbed1705d
SHA256
ffaada30555030aa16a5ed7365a4d1f291a193899f4169a340c591774e0a662d
MD5
c6642362f41eb191363e8c4023c13c13

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antivm_queries_computername: Retrieves the computer name

Other

yara_rules: Static rules
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card