Managed XDR

payment.eml — malware analysis report

File info

Filename
payment.eml
File type
RFC 822 mail, ASCII text, with very long lines, with CRLF line terminators
File size
384.9 KB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
b660b22cff46973513b4a398c0f8979cabac166c
SHA256
e9567a48a188d2289a30c49f4d940201c964001b3d9cf9623d2b6a98c23e1b46
MD5
aedab6d3078392a074a59f5c3d8e36b9

Signatures

Initial Access

T1192 html_urls: HTML-document downloads a file

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497 office_security_check: Checks Microsoft Office security settings
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization
T1497.002 async_mouse: Watches for mouse clicks using GetAsyncKeyState to detect human activity
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497 office_security_check: Checks Microsoft Office security settings
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization
T1497.002 async_mouse: Watches for mouse clicks using GetAsyncKeyState to detect human activity

Other

suspicious_pdf_link: PDF file with suspicious hyperlink or content
suspicious_pdf: PDF file with suspicious content
pdf_page: Contains only one page
create_rpc_bindings: Creates RPC connection
pdf_compressed_stream: Contains an object with compressed stream
creates_suspended_process: Creates suspended process
suspicious_network_port: Performs TCP or UDP request to non-standard port
test_check_service: Starts services
office_links: Office file contains external links
checktokenmembership: Checks user token with CheckTokenMembership call