Managed XDR

scratch-zoo-2025-03-07...0612e2aba726c871a7f03d — malware analysis report

File info

Filename
scratch-zoo-2025-03-07-5e99b051320612e2aba726c871a7f03d
File type
SMTP mail, ASCII text, with very long lines
File size
3.2 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
5f374769dfb9d1bb300e8c349f6d3f5fb13951ec
SHA256
36cf442112187e04ec4834d983be0c0d8237cf7db6f57cc4020413ba64af9088
MD5
5e99b051320612e2aba726c871a7f03d

Signatures

Privilege Escalation

T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
get_policy_info: Retrieves information about a Policy object
dotnet_suspicious_entrypoint: Dotnet program has suspicious entrypoint
dotnet_suspicious_module_name: Dotnet program has suspicious module name