Managed XDR

analisis.eml — malware analysis report

File info

Filename
analisis.eml
File type
RFC 822 mail, ASCII text, with very long lines, with CRLF line terminators
File size
31 KB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
b92fae73a60ccaabb044f68977b2ec66071bb4e8
SHA256
02486d673810f8c751efdb105ec6622cf5797399f07f304f48266d4f537b191c
MD5
29c487496cbd54f5cbec100218b57a92

Signatures

Initial Access

T1192 html_urls: HTML-document downloads a file

Execution

T1059.005 bad_vbs: Suspicious VBScript file
T1059.005 obfuscated_vbs: Detected obfuscated VBS
T1047 antivm_wmi: Uses WMI to detect virtual environment
T1047 has_wmi: Executes one or several WMI requests

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027 obfuscated_vbs: Detected obfuscated VBS
T1497.001 antivm_wmi: Uses WMI to detect virtual environment
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1555.004 windows_credential_manager: Acquire credentials from the Windows Credential Manager

Discovery

T1497.001 antivm_wmi: Uses WMI to detect virtual environment
T1057 has_wmi: Executes one or several WMI requests
T1082 has_wmi: Executes one or several WMI requests
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization
T1135 server_share_info: Retrieves information about each shared resource on a server

Command and Control

T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp

Other

network_bind: Starts servers listening at None
pdf_page: Contains only one page
create_rpc_bindings: Creates RPC connection
has_pdb: This executable file has a PDB path
creates_suspended_process: Creates suspended process
dotnet_import_unmanaged_code: Dotnet program statically imports unmanaged functions/modules
message_box: Displays a message
suspicious_network_port: Performs TCP or UDP request to non-standard port
test_check_service: Starts services
checktokenmembership: Checks user token with CheckTokenMembership call
pe_overlay: PE file contains overlay