Managed XDR

20250616_fp_100_108.eml — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
20250616_fp_100_108.eml
Тип файла
SMTP mail, ASCII text, with very long lines
Размер файла
158.1 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
33a14d38bd19efe281d6e968b46e4656ed1b1dd8
SHA256
b408a528ca913dc65f38ee289b4b34a628370546e5b21d46a086a1a2f97733e8
MD5
f9dd5e7e0746f517c4446c816612615c

Сигнатуры

Execution

T1059 network_wscript_downloader: Wscript.exe initiated network communication
T1059.005 obfuscated_vbs: Detected obfuscated VBS

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027 obfuscated_vbs: Detected obfuscated VBS
T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files

Discovery

T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Command and Control

T1071 network_wscript_downloader: Wscript.exe initiated network communication
T1071.001 network_http: Performs HTTP requests
T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp

Other

modifies_certs: Attempts to generate or modify system certificates
no_graphical_activity: No graphic activity
create_rpc_bindings: Creates RPC connection
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
checktokenmembership: Checks user token with CheckTokenMembership call
Managed XDR