Managed XDR

rv_-cobro-juridico.msg — malware analysis report

File info

Filename
rv_-cobro-juridico.msg
File type
CDFV2 Microsoft Outlook Message
File size
2.9 MB
First seen
Last seen

Environment

win7/x64 en

Hashes

SHA1
fece4575de86c4aa22ea2d61b9e11ea37f29f223
SHA256
5d6a2160a7af5bc41acbf2099387169d9d20a1a8a1ce36f516e55610144a49be
MD5
612f2b7b1f1f08837d5b9d59b7c6e005

Signatures

Execution

T1059.001 suspicious_powershell: Creates suspicious powershell process

Privilege Escalation

T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1036 copies_utilities: Copies and runs system utility with different name
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

creates_exe: Creates executable files in the file system
executes_dropped_exe: Executes dropped exe files
no_graphical_activity: No graphic activity