Managed XDR

2401216im_34-fhj-721-_-ithala_260761.eml — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
2401216im_34-fhj-721-_-ithala_260761.eml
Тип файла
RFC 822 mail, ASCII text, with CRLF line terminators
Размер файла
697.8 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
e2cd9d4d9aad212517ba3daa4e8f0fa36361d453
SHA256
e47e8214d6c429b7db9e5082fd39ac97bb61b4f4546ea90b5d754b42364d9372
MD5
ee0df83343de4109b00316c53823b1cd

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1036.001 invalid_authenticode: Digital signature of the executable file has failed the verification
T1027.002 nsis_archive: One of the packages is NSIS archive
T1480 system_default_lang_id_present: Checks the system language
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
error_drawtext: An error occured while executing the file
pe_overlay: PE file contains overlay