Managed XDR

96c7b9f2-375f-414b-508...-7490-f854504f9ea4.eml — malware analysis report

File info

Filename
96c7b9f2-375f-414b-5080-08deebe6be49-4eac7664-c346-5be7-7490-f854504f9ea4.eml
File type
RFC 822 mail, ASCII text, with very long lines, with CRLF line terminators
File size
125.9 KB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
44f41938682bd100dd8ae91766120f6dcb59bc35
SHA256
a6b7ee51b477157f5c3831d9500d869ea099a44310cc166a8724a2ce05e1bd62
MD5
8a536d1c0b2defb47dd865f8ef434e35

Signatures

Initial Access

T1192 html_urls: HTML-document downloads a file

Execution

T1569.002 persistence_service: Starts newly created service
T1047 antivm_wmi: Uses WMI to detect virtual environment
T1047 has_wmi: Executes one or several WMI requests
T1059 wscript_info_discovery: Collects info about system with Wscript.Shell
T1059.001 url_cmdline: Cmdline of process contains URL
T1059.003 url_cmdline: Cmdline of process contains URL

Persistence

T1547.002 persistence_autorun: Makes itself run automatically on Windows startup
T1543.003 creates_service: Creates a service, that will start automatically
T1574 dropper_dll: Creates DLL, which is then loaded into the process

Privilege Escalation

T1547.002 persistence_autorun: Makes itself run automatically on Windows startup
T1543.003 creates_service: Creates a service, that will start automatically
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1218 suspicious_cmdline: Executes a suspicious command
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1070 stealth_webhistory: Clears browsing history
T1036 system_filename: Created a file named as a common system file
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1497 office_security_check: Checks Microsoft Office security settings
T1497.001 antivm_wmi: Uses WMI to detect virtual environment
T1497.003 antisandbox_idletime: Detects Windows Idle Time to determine the uptime
T1497.001 antivm_network_adapters: Checks NIC addresses
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization
T1497.001 antivm_queries_computername: Retrieves the computer name
T1497.002 async_mouse: Watches for mouse clicks using GetAsyncKeyState to detect human activity
T1070 stealth_window: A process created a hidden window

Credential Access

T1555.004 windows_credential_manager: Acquire credentials from the Windows Credential Manager

Discovery

T1033 sam_users_discovery: Enumerates users or groups in system with SAM API
T1057 has_wmi: Executes one or several WMI requests
T1497 office_security_check: Checks Microsoft Office security settings
T1497.001 antivm_wmi: Uses WMI to detect virtual environment
T1497.003 antisandbox_idletime: Detects Windows Idle Time to determine the uptime
T1082 has_wmi: Executes one or several WMI requests
T1497.001 antivm_network_adapters: Checks NIC addresses
T1087.001 local_account_discovery: Enumerates local accounts
T1049 list_ts_rdp_sessions: Lists ts/rdp sessions
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization
T1497.001 antivm_queries_computername: Retrieves the computer name
T1497.002 async_mouse: Watches for mouse clicks using GetAsyncKeyState to detect human activity
T1082 wscript_info_discovery: Collects info about system with Wscript.Shell

Command and Control

T1105 cmdline_curl: Uses curl utility for network data transferring
T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp
T1071.001 wininet_https: Performs HTTP/HTTPS requests using WinInet

Exfiltration

T1022 encrypts_pc_info: Collects and encrypts information about the computer (possibly for exfiltration)

Other

creates_in_windows: Creates files in the Windows directory
multiple_useragents: Uses more than one unique User-Agent
network_bind: Starts servers listening at 127.0.0.1:0, None
creates_exe: Creates executable files in the file system
pdf_page: Contains only one page
creates_doc: Creates (office) documents in the file system
executes_dropped_exe: Executes dropped exe files
create_rpc_bindings: Creates RPC connection
pdf_compressed_stream: Contains an object with compressed stream
creates_suspended_process: Creates suspended process
suspicious_network_port: Performs TCP or UDP request to non-standard port
test_check_service: Starts services
office_links: Office file contains external links
checktokenmembership: Checks user token with CheckTokenMembership call
open_winlogon_process: Trying to open winlogon process