Managed XDR

release_-2603786-_-esz...o__869dr1yqz__tsl-.eml — malware analysis report

File info

Filename
release_-2603786-_-eszcy26060888-cfm-fcl-imp-1309-2026-__-exw-guangdong-gda-__-1x40hc-__-cnee.-innpro-elegoo__869dr1yqz__tsl-.eml
File type
SMTP mail, ASCII text, with CRLF line terminators
File size
177.9 KB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
2ace4d80a6b6146daf5548947d5b756d527dab37
SHA256
ffe9878864bbb5c5524656fd07b939b5b7f1080aec54220f1ecef310bb67b76b
MD5
56a333359412e7ba4156ae49fc878ca6

Signatures

Execution

T1059.001 suspicious_powershell: Creates suspicious PowerShell process
T1059.007 bad_js: Suspicious Javascript file
T1059.001 suspicious_process: Spawns a suspicious process
T1047 antivm_wmi: Uses WMI to detect virtual environment
T1047 has_wmi: Executes one or several WMI requests

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.001 antivm_wmi: Uses WMI to detect virtual environment
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization
T1070 stealth_window: A process created a hidden window
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1555.004 windows_credential_manager: Acquire credentials from the Windows Credential Manager

Discovery

T1497.001 antivm_wmi: Uses WMI to detect virtual environment
T1057 has_wmi: Executes one or several WMI requests
T1082 has_wmi: Executes one or several WMI requests
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization

Command and Control

T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp

Other

network_bind: Starts servers listening at None
create_rpc_bindings: Creates RPC connection
creates_suspended_process: Creates suspended process
suspicious_network_port: Performs TCP or UDP request to non-standard port
test_check_service: Starts services