Managed XDR

613699424.eml (Mydoom) — malware analysis report

File info

Filename
613699424.eml
File type
SMTP mail, ASCII text, with very long lines, with CRLF line terminators
File size
76.4 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
a9bb9fee31dc3f86032612a34845c858e15b75b4
SHA256
c63730d4951e14bac66b0acd3895a50e093c08a8022a847bc992f26b0746b377
MD5
c9c2002657149b58d2be683d713f6a64

Malwares

  • Mydoom

Signatures

Persistence

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup

Privilege Escalation

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_polymorphic: Creates a modified copy of itself
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1552 infostealer_browser: Retrieves personal information from local Internet browsers
T1503 infostealer_browser: Retrieves personal information from local Internet browsers
T1555.003 cookie_files: Accesses cookie files
T1555.004 windows_credential_manager: Acquire credentials from the Windows Credential Manager
T1552 cookie_files: Accesses cookie files

Discovery

T1083 crawls_directories: Opens a huge number of directories all over disk C: (possibly, searches for sensitive data)
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1518 locates_browser: Attempts to identify where browsers are installed

Command and Control

T1071.003 network_smtp: Sends emails, possibly SPAM

Impact

T1565 modifies_hostfile: Writes data to system hosts file

Other

yara_rules: Static rules
suricata_alert: Malicious traffic detected
creates_exe: Creates executable files in the file system
executes_dropped_exe: Executes dropped exe files
creates_in_windows: Creates files in the Windows directory
copies_self: Creates a copy of itself
network_bind: Starts servers listening at 0.0.0.0:36276
dns_without_resolve: DNS query without a response
network_ftp: Performs FTP requests
no_graphical_activity: No graphic activity
access_recyclebin: Manipulation with recyclebin detected
get_policy_info: Retrieves information about a Policy object
pe_overlay: PE file contains overlay

Related reports