Managed XDR

0-1rtnid-0006do-6i.eml — malware analysis report

File info

Filename
0-1rtnid-0006do-6i.eml
File type
ASCII text, with very long lines
File size
104.1 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
05eb104e0caf4aab29f3a81e4941d474d60e7fba
SHA256
10b1ed3962429c89358beeb97310012c9b4b4148d5cc3923f4e47978744aadde
MD5
d443e2c5ba28b88e732367229ce61fee

Signatures

Execution

T1059.001 suspicious_powershell: Creates suspicious powershell process
T1059.001 suspicious_process: Spawns a suspicious process

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1518 locates_browser: Attempts to identify where browsers are installed

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
no_graphical_activity: No graphic activity
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object