Managed XDR

order.eml — malware analysis report

File info

Filename
order.eml
File type
SMTP mail, ASCII text, with very long lines, with CRLF line terminators
File size
2.7 MB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
e1b9b76c0d3ae989c0c4a7c2d7fd1bf411cfc9be
SHA256
dc01ac0bacde149c78583813e00949b335cf3a71330b784873869e8418935c85
MD5
9ae77239071bbd08a58a7fa1a663655f

Signatures

Privilege Escalation

T1055.002 inject_write_pe: Writes PE file to another process's memory
T1055.012 injection_runpe: Injects code into another process
T1055 injection_failed: The attempt to inject into a process has failed
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1055.002 inject_write_pe: Writes PE file to another process's memory
T1055.012 injection_runpe: Injects code into another process
T1027.002 unnamed_memory_regions_contains_pe: One or several unnamed memory regions are PE files
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1497 manual_ntdll_load: Creates copy of ntdll.dll in memory
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1497 antidbg_query_system: Checks for kernel debugger (SystemKernelDebuggerInformation)
T1497 antidbg_query_process: Checks if the process is being debugged (ProcessDebugPort)
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1055 injection_failed: The attempt to inject into a process has failed
T1070 stealth_window: A process created a hidden window

Credential Access

T1555.004 windows_credential_manager: Acquire credentials from the Windows Credential Manager

Discovery

T1497 manual_ntdll_load: Creates copy of ntdll.dll in memory
T1497 antidbg_query_system: Checks for kernel debugger (SystemKernelDebuggerInformation)
T1497 antidbg_query_process: Checks if the process is being debugged (ProcessDebugPort)
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization
T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Command and Control

T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp

Other

steganographic_png: Possible malicious steganographic PNG
crashed_suspicious_dotnet: An error occurred while executing a highly suspicious Mono/.Net file
unpacker_wrong_base: Possibly, an error occurred in the file unpacker
network_bind: Starts servers listening at None
process_crashed: One of the processes has failed
no_graphical_activity: No graphic activity
dotnet_suspicious_module_name: Dotnet program has suspicious module name
creates_suspended_process: Creates suspended process
suspicious_network_port: Performs TCP or UDP request to non-standard port
test_check_service: Starts services
checktokenmembership: Checks user token with CheckTokenMembership call
yara_rules: Static rules