Managed XDR

fw-re-top-urgent-shipping-documents.msg — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
fw-re-top-urgent-shipping-documents.msg
Тип файла
CDFV2 Microsoft Outlook Message
Размер файла
1.9 MB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x64 en

Хеши

SHA1
4d399fcf0d934394b946c06ebde9e3b9e1a3f4e5
SHA256
4ab50c62d2e8bc03a1dee6dc040fb57ae2cab4e6d248ae8b46744db19aecab22
MD5
f49a76eeede70fe2066570a27afd6a23

Сигнатуры

Execution

T1059.001 suspicious_powershell: Creates suspicious powershell process
T1059.003 suspicious_batch: Suspicious batch

Privilege Escalation

T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1036 copies_utilities: Copies and runs system utility with different name
T1564.001 stealth_file: Creates hidden or system files
T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antivm_queries_computername: Retrieves the computer name

Other

executes_dropped_exe: Executes dropped exe files
no_graphical_activity: No graphic activity