Managed XDR

eml000f89e6.tmp — malware analysis report

File info

Filename
eml000f89e6.tmp
File type
SMTP mail, ASCII text, with very long lines, with CRLF line terminators
File size
27.3 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
93d97d0df5a212bcd797c5517ac16e088e0ed2a3
SHA256
080b460e3a0015e543325278e6b845165f95a625ffba580bf255b051df907fe7
MD5
7ec5c7050d19c9789df7b5e73e228f4a

Signatures

Execution

T1064 office_macros_suspicious: Document contains suspicious macro
T1064 office_macros: The document contains macro
T1064 office_macros_strings: Feature lines found in document macro

Privilege Escalation

T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1221 office_attached_template: Office file attempts to download a suspicious template from the Internet
T1064 office_macros_suspicious: Document contains suspicious macro
T1064 office_macros: The document contains macro
T1064 office_macros_strings: Feature lines found in document macro
T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antivm_queries_computername: Retrieves the computer name

Other

yara_rules: Static rules
create_rpc_bindings: Creates RPC connection
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
office_links: Office file contains external links
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card