Managed XDR

2786b462-16be-37fd-e295-280d8ec8dbe0.eml — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
2786b462-16be-37fd-e295-280d8ec8dbe0.eml
Тип файла
RFC 822 mail, ASCII text, with very long lines, with CRLF line terminators
Размер файла
23.6 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
aa262dd062cab5474d3105e98dd85fde1022dbc0
SHA256
a64a8aab7f9739591f14eeeffe2d8e782a82f1e6d0e044c40fea507ee3ea4267
MD5
a0e5cc6ee3c2ee84884d18e92b28c679

Сигнатуры

Execution

T1059.001 suspicious_powershell: Creates suspicious powershell process
T1204.002 mimics_extension: Attempts to mimic the file extension
T1059.001 suspicious_process: Spawns a suspicious process
T1059.001 url_cmdline: Cmdline of process contains URL
T1059.003 suspicious_batch: Suspicious batch
T1059.003 url_cmdline: Cmdline of process contains URL

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1036 mimics_extension: Attempts to mimic the file extension
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
checktokenmembership: Checks user token with CheckTokenMembership call
Managed XDR