Managed XDR

1-1632266610.m386780p1...et-s-92376-w-93684_2-s (CloudEyE) — malware analysis report

File info

Filename
1-1632266610.m386780p1089693.a2plcpnl0073.prod.iad2.secureserver.net-s-92376-w-93684_2-s
File type
SMTP mail, UTF-8 Unicode text
File size
90.2 KB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
ef609dfde01ca4cf10d27b65468fd4f8a16b501a
SHA256
b8dc777400877b239dbc8aeb97c28d9f7927963b1b1c4453a26f0f9b89746c6a
MD5
305531f1adaca8531f7f18f92ab11123

Malwares

  • CloudEyE

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1045 guloader_behaviour2: Cloudeye/GuLoader specific behavior has been detected
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1480 system_default_lang_id_present: Checks the system language
T1134 opens_process_token: Opens the access token associated with a process
T1027.002 packer_vb: The executable file is packed using VB
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization

Credential Access

T1555.004 windows_credential_manager: Acquire credentials from the Windows Credential Manager

Discovery

T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization

Command and Control

T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp

Other

yara_rules: Static rules
network_bind: Starts servers listening at None
suspicious_network_port: Performs TCP or UDP request to non-standard port
test_check_service: Starts services
checktokenmembership: Checks user token with CheckTokenMembership call

Related reports

Managed XDR