Managed XDR

4.20260805.20270221.52....cvspambo002.wmail.eml — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
4.20260805.20270221.525186.22509.140241663932160.1.spamreport_phishing.web.cvspambo002.wmail.eml
Тип файла
HTML document, ASCII text, with CRLF line terminators
Размер файла
57.8 KB
Первое обнаружение
Последнее обнаружение

Окружение

w10/x64 en

Хеши

SHA1
55ffe5ef5dc93950bdcae0be9b4f30ca83271d32
SHA256
5f9fb74444318e4a8bf2ae3b80bfe9f6196aef719e339c38b0dfb90904bdcbee
MD5
257a686b8324230782973c311c1b0d85

Сигнатуры

Initial Access

T1192 html_urls: HTML-document downloads a file

Execution

T1059.003 cmd_ping_del: Uses cmd.exe for pausing and deletion of the original file
T1047 antivm_wmi: Uses WMI to detect virtual environment
T1047 has_wmi: Executes one or several WMI requests

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1070.004 cmd_ping_del: Uses cmd.exe for pausing and deletion of the original file
T1497.001 antivm_wmi: Uses WMI to detect virtual environment
T1497.003 antisandbox_sleep_utilities: Uses Windows utilities for pausing the execution
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1555.004 windows_credential_manager: Acquire credentials from the Windows Credential Manager

Discovery

T1057 has_wmi: Executes one or several WMI requests
T1497.001 antivm_wmi: Uses WMI to detect virtual environment
T1497.003 antisandbox_sleep_utilities: Uses Windows utilities for pausing the execution
T1082 has_wmi: Executes one or several WMI requests
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization
T1016.001 system_network_configuration_discovery: System network configuration discovery detected

Command and Control

T1071.001 network_http: Performs HTTP requests
T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp

Other

suricata_alert: Malicious traffic detected
yara_rules: Static rules
creates_exe: Creates executable files in the file system
ip_domains: Identifies an IP address using external resources
network_bind: Starts servers listening at None
creates_in_windows: Creates files in the Windows directory
creates_suspended_process: Creates suspended process
creates_in_programdata: Creates files in the ProgramData directory
suspicious_network_port: Performs TCP or UDP request to non-standard port
test_check_service: Starts services