Managed XDR

mailler.exe — malware analysis report

File info

Filename
mailler.exe
File type
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
File size
3.4 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
8a2006700c0950d64a6ebec8698c506b4433a442
SHA256
cb1b429cd203a995b05d3f6fcffd703ab78f79d24b6b08a856b0b8a08f564347
MD5
5f75581fa0e22156e33f5f8460cefc1e

Signatures

Execution

T1059.003 suspicious_batch: Suspicious batch

Privilege Escalation

T1055.012 injection_runpe: Injects code into another process
T1055 sets_debug_registers: Sets debug registers for a thread in a different process
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1070.004 deletes_self: Moves to different location or removes the original executable file
T1055.012 injection_runpe: Injects code into another process
T1027.002 unnamed_memory_regions_contains_pe: One or several unnamed memory regions are PE files
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1055 sets_debug_registers: Sets debug registers for a thread in a different process
T1497.003 antisandbox_sleep_utilities: Uses Windows utilities for pausing the execution
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1070 stealth_window: A process created a hidden window

Discovery

T1497.003 antisandbox_sleep_utilities: Uses Windows utilities for pausing the execution
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1016.001 system_network_configuration_discovery: System network configuration discovery detected
T1082 fingerprint_to_file: Collects data about system and user and writes it to a text file

Command and Control

T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp

Other

yara_rules: Static rules
creates_exe: Creates executable files in the file system
dead_host: Connects to IP addresses that do not respond to requests
no_graphical_activity: No graphic activity
creates_suspended_process: Creates suspended process
pe_overlay: PE file contains overlay