Managed XDR

6321554a-6166-46fd-15f...-9625-ece8f1e36039.eml (NetSupport RAT) — malware analysis report

File info

Filename
6321554a-6166-46fd-15f9-08dd3492dac7-583b8a6b-9628-cfa8-9625-ece8f1e36039.eml
File type
RFC 822 mail, ASCII text, with CRLF line terminators
File size
142.8 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
ede775935a4c89aa53875a9d00ea02731ad4ab92
SHA256
903534e1344898a318e90da2ca8668b14ef2ea7ff5b8e6cd9cee8a2bd37900f8
MD5
e9cda4bfc8c8a7ebe33e0952f29f7c90

Malwares

  • NetSupport RAT

Signatures

Execution

T1059 network_wscript_downloader: Wscript.exe initiated network communication
T1047 antivm_wmi: Uses WMI to detect virtual environment
T1047 has_wmi: Executes one or several WMI requests

Persistence

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup

Privilege Escalation

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1070.004 deletes_self_script: Moves to different location or removes the original executable file
T1564.001 stealth_file: Creates hidden or system files
T1497.001 antivm_wmi: Uses WMI to detect virtual environment
T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files

Discovery

T1497.001 antivm_wmi: Uses WMI to detect virtual environment
T1082 has_wmi: Executes one or several WMI requests
T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Command and Control

T1071 network_wscript_downloader: Wscript.exe initiated network communication
T1071.001 network_cnc_http: Suspicious HTTP traffic
T1071.001 network_http: Performs HTTP requests
T1071.001 wininet_https: Performs HTTP/HTTPS requests using WinInet

Other

suricata_alert: Malicious traffic detected
creates_exe: Creates executable files in the file system
suspicious_pdf: PDF file with suspicious content
pdf_page: Contains only one page
create_rpc_bindings: Creates RPC connection
pdf_compressed_stream: Contains an object with compressed stream
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object
creates_in_programdata: Creates files in the ProgramData directory
test_check_service: Starts services
suspicious_pdf_link: PDF file with suspicious hyperlink or content
office_links: Office file contains external links
checktokenmembership: Checks user token with CheckTokenMembership call

Related reports