Managed XDR

forwardedmessage.eml — malware analysis report

File info

Filename
forwardedmessage.eml
File type
SMTP mail, ASCII text, with very long lines, with CRLF line terminators
File size
28.5 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
69bf017abbe93d6c25740342a1b82741ed68f566
SHA256
9fcac7fe27e4cf373963d49c2a5faac7b4a9a271db2704bff86771956e57bfe3
MD5
2621f519e97f4d4bfc2aa6e31855507c

Signatures

Execution

T1059.001 suspicious_powershell: Creates suspicious powershell process
T1059 powershell_cmd_longcommandline: Suspiciously long commandline
T1204.002 mimics_extension: Attempts to mimic the file extension
T1047 has_wmi: Executes one or several WMI requests
T1059.001 suspicious_process: Spawns a suspicious process
T1059.005 obfuscated_vbs: Detected obfuscated VBS

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1036 mimics_extension: Attempts to mimic the file extension
T1070 stealth_window: A process created a hidden window
T1027 obfuscated_vbs: Detected obfuscated VBS
T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1057 has_wmi: Executes one or several WMI requests
T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1082 reads_csrss: Attempts to read csrss.exe memory
T1016.001 system_network_configuration_discovery: System network configuration discovery detected

Other

yara_rules: Static rules
dns_without_resolve: DNS query without a response
no_graphical_activity: No graphic activity
get_policy_info: Retrieves information about a Policy object
checktokenmembership: Checks user token with CheckTokenMembership call
suricata_alert: Malicious traffic detected