Managed XDR

statement-of-account-f...2344c8a4e9bc1f2d7b.eml — malware analysis report

File info

Filename
statement-of-account-for-august-2024-p-jeffrey.ang-accounts.sg-sg.gaig.com-2024-09-30-9db21561527a9778b3968ef14415f7c0edd2419c989d1a2344c8a4e9bc1f2d7b.eml
File type
RFC 822 mail, ASCII text, with CRLF line terminators
File size
1.2 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
087fdcc66d90598a675d90f93bdb92ebdcf018ae
SHA256
44633df8a91c2c11425f726416b911d4924d41ceaa6d1152093d2145d4eff342
MD5
2d1a270c6876b5aca8d410a4525c411d

Signatures

Execution

T1204.002 mimics_extension: Attempts to mimic the file extension
T1059.001 suspicious_powershell: Creates suspicious powershell process
T1059 nsis_suspicious_filenames: Nsis contains files with suspicious names

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1036.001 invalid_authenticode: Digital signature of the executable file has failed the verification
T1036 mimics_extension: Attempts to mimic the file extension
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1027.002 nsis_archive: One of the packages is NSIS archive
T1027.002 nsis_suspicious_filenames: Nsis contains files with suspicious names
T1480 system_default_lang_id_present: Checks the system language
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
creates_exe: Creates executable files in the file system
pe_overlay: PE file contains overlay