Managed XDR

fw-kpmg-tax-walkthroug...ntrols-placeholder.msg — malware analysis report

File info

Filename
fw-kpmg-tax-walkthrough-corporation-tax-rdec-annual-ye-controls-placeholder.msg
File type
CDFV2 Microsoft Outlook Message
File size
5.1 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
c87761f12d6cddf0e407bfb220a46485b8ce7913
SHA256
b38a3eb24b48091ebf8342491e52bd8b8e19e3994477ffe07aabb857bcc6529c
MD5
cb9a66ffeff0ee5401f4f6d24ba9ae18

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card