Managed XDR

da869926-4fbe-47fc-3a8...-3efb-d4ba86467b7b.eml — malware analysis report

File info

Filename
da869926-4fbe-47fc-3a8e-08dd30ea3d88-bd404a0b-2b26-ade5-3efb-d4ba86467b7b.eml
File type
ASCII text, with CRLF line terminators
File size
10.4 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
63c1cd4cc6401e78e961d12fc3ffed44e8ed23a3
SHA256
ac773d12fae3235ed58fb752f71ce726393cde95c6a929bf6dc89bb29e16df0d
MD5
ee053b285ec43f4f36a5a29c5f6e67b6

Signatures

Execution

T1059.001 suspicious_powershell: Creates suspicious powershell process
T1059.007 bad_js: Suspicious Javascript file
T1059.001 suspicious_process: Spawns a suspicious process
T1059.001 url_cmdline: Cmdline of process contains URL
T1059.003 url_cmdline: Cmdline of process contains URL

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1070 stealth_window: A process created a hidden window
T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Command and Control

T1102.003 references_google: Contains links to cloud services of Google (potentially for malicious payload delivery)

Other

modifies_certs: Attempts to generate or modify system certificates
no_graphical_activity: No graphic activity
get_policy_info: Retrieves information about a Policy object
checktokenmembership: Checks user token with CheckTokenMembership call