Managed XDR

re-fatura.eml — malware analysis report

File info

Filename
re-fatura.eml
File type
SMTP mail, ASCII text, with CRLF line terminators
File size
23.1 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
e46bdf2870573f279729a51e01f17478117508e3
SHA256
ba68d035bba7823a8c630a555fe45091820f2b77605039462a78aa6307eac1ec
MD5
cbb03b24ee6c68c18ac808f0dfd2a01c

Signatures

Initial Access

T1192 html_urls: HTML-document downloads a file

Persistence

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup

Privilege Escalation

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1033 recon_beacon: The process has sent information about the computer over the network

Command and Control

T1071.001 recon_beacon: The process has sent information about the computer over the network

Other

creates_in_programdata: Creates files in the ProgramData directory