Managed XDR

5g.eml — malware analysis report

File info

Filename
5g.eml
File type
HTML document, ASCII text, with very long lines, with CRLF line terminators
File size
570.2 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
9859d7c97d03a8604519380139efb32f27f92912
SHA256
3e96e48ff288099c82a7721461fd501cbbc956db5e9c5956e0ebf61eb1456cac
MD5
7c1736d4162d1cfe2dd87a67cff89863

Signatures

Execution

T1203 exploit_CVE_2017_11882: Exploits CVE-2017-11882 vulnerability
T1203 office_exploit_http: The document exhibits suspicious behaviour (performs HTTP requests)

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files

Command and Control

T1071.001 office_exploit_http: The document exhibits suspicious behaviour (performs HTTP requests)
T1071.004 office_exploit_dns: The document exhibits suspicious behaviour (performs DNS requests)
T1071.001 wininet_https: Performs HTTP/HTTPS requests using WinInet

Other

yara_rules: Static rules
create_process_failed: Could not start the process
suspicious_process_network: Unusual process network activity detected
dns_without_resolve: DNS query without a response
unexpected_exception: Unexpected exception
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card
suricata_alert: Malicious traffic detected