Managed XDR

4.20240513.20241129.87....cvspambo001.wmail.eml (CloudEyE) — malware analysis report

File info

Filename
4.20240513.20241129.872538.23363.140471553206016.1.spamreport.web.cvspambo001.wmail.eml
File type
HTML document, ASCII text, with very long lines, with CRLF line terminators
File size
399.7 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
245c5d59d8e181c85c9cf089e30cd4964b08586c
SHA256
2810d3ad2da2562875de37d216197d7725a5b208389a132094201e279f426f8f
MD5
bd30a2900f28206cb3d75c76afda2c8b

Malwares

  • CloudEyE

Signatures

Initial Access

T1192 html_urls: HTML-document downloads a file

Execution

T1059.001 suspicious_powershell: Creates suspicious powershell process
T1059 powershell_cmd_longcommandline: Suspiciously long commandline
T1059.001 suspicious_process: Spawns a suspicious process
T1059.003 suspicious_process: Spawns a suspicious process
T1047 has_wmi: Executes one or several WMI requests
T1059.005 obfuscated_vbs: Detected obfuscated VBS

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1070 stealth_window: A process created a hidden window
T1027 obfuscated_vbs: Detected obfuscated VBS
T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1057 has_wmi: Executes one or several WMI requests
T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1082 reads_csrss: Attempts to read csrss.exe memory
T1016.001 system_network_configuration_discovery: System network configuration discovery detected

Command and Control

T1102.003 references_discord: Contains links to cloud services of Discord (potentially for malicious payload delivery)

Other

yara_rules: Static rules
modifies_certs: Attempts to generate or modify system certificates
dns_without_resolve: DNS query without a response
unexpected_exception: Unexpected exception
no_graphical_activity: No graphic activity
get_policy_info: Retrieves information about a Policy object
checktokenmembership: Checks user token with CheckTokenMembership call

Related reports