Managed XDR

7638ac08-400f-ec06-8548-7bde665c44e3.eml — malware analysis report

File info

Filename
7638ac08-400f-ec06-8548-7bde665c44e3.eml
File type
RFC 822 mail, ASCII text, with very long lines, with CRLF line terminators
File size
115.5 KB
First seen
Last seen

Environment

win7/x64 en

Hashes

SHA1
1b17a820452d1d1fc86fd9f9f07c5b8795f947b8
SHA256
b03f27e2d1f481da138864457ace7bdb4d57dd8af71af3f8993f8b99f3a1e07a
MD5
9ebce019833214b21f582f19567be742

Signatures

Execution

T1204.002 mimics_extension: Attempts to mimic the file extension

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.001 antivm_vbox_keys: Detects VirtualBox through the presence of a registry key
T1036 mimics_extension: Attempts to mimic the file extension
T1497.001 antivm_disk_size: Checks the amount of free disk space
T1497 evasion_diskenum: Sandbox evasion using enumeration of partitions
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antivm_vbox_keys: Detects VirtualBox through the presence of a registry key
T1497.001 antivm_disk_size: Checks the amount of free disk space
T1057 process_interest: Enumerates processes
T1497 evasion_diskenum: Sandbox evasion using enumeration of partitions

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
message_box: Displays a message
pe_overlay: PE file contains overlay