Managed XDR

message__2025040822101...netsignatureq_pro_.eml — malware analysis report

File info

Filename
message__20250408221015_7cec4372ca49588b_netsignatureq_pro_.eml
File type
ASCII text, with CRLF line terminators
File size
23.5 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
ccf3f5e83eca40be3c9a51b268ee2cb4e32ee750
SHA256
7c75c9abc4f657bfb837530726e381bf12808333df0ba61fddb7ed7433f6a513
MD5
9d7efaacf431312a3f215aace32e1407

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Command and Control

T1071.001 network_http: Performs HTTP requests

Other

networkdyndns_checkip: Connects to a Dynamic DNS domain
yara_rules: Static rules
ip_domains: Identifies an IP address using external resources
creates_in_programdata: Creates files in the ProgramData directory