Managed XDR

message.eml — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
message.eml
Тип файла
UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
Размер файла
14.4 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
c108111d7ca55bbf3817f728b88d9ddfe83a1033
SHA256
9de568e936f5491e8e3970ae5aafa991c7ccc2d3ae6f31787a335439b9978b2b
MD5
d284e839bd49860171da3f9f0e1cae1d

Сигнатуры

Initial Access

T1192 html_urls: HTML-document downloads a file

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1027.002 packer_entropy: Probably contains compressed or encrypted data

Discovery

T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Other

yara_rules: Static rules