Managed XDR

mail.eml — malware analysis report

File info

Filename
mail.eml
File type
RFC 822 mail, UTF-8 Unicode text
File size
578.1 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
a7dbe6fc5a60328c454b7b7f1103d10ecb85e974
SHA256
29de18358d410e037c585290194484c0c9de664642b8d64c6f6f2a52a3a3b50f
MD5
66233773772b285defd1b4c35aac9a93

Signatures

Execution

T1569.002 persistence_service: Starts newly created service

Persistence

T1543.003 creates_service: Creates a service, that will start automatically

Privilege Escalation

T1543.003 creates_service: Creates a service, that will start automatically
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 unnamed_memory_regions_contains_pe: One or several unnamed memory regions are PE files
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
dead_host: Connects to IP addresses that do not respond to requests
no_graphical_activity: No graphic activity
test_check_service: Starts services
Managed XDR