Managed XDR

000000002.eml — malware analysis report

File info

Filename
000000002.eml
File type
RFC 822 mail, ASCII text, with very long lines, with CRLF line terminators
File size
427.6 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
e89926303b8dd18063a034fc2e62fc8720bb91bd
SHA256
f0610cf8158cede72e58f671cbc352fabcdfd417449ea3c103ece1c2cef3c1e4
MD5
801714cf732041ce952bc6bf4251428c

Signatures

Initial Access

T1192 html_urls: HTML-document downloads a file

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
message_box: Displays a message
error_drawtext: An error occured while executing the file
checktokenmembership: Checks user token with CheckTokenMembership call