Managed XDR

swedbank-2025-04-08-2016.eml — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
swedbank-2025-04-08-2016.eml
Тип файла
ASCII text, with CRLF line terminators
Размер файла
26.6 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
bcb5510b7a8bacd3ce2a1a5daa83149796921e6c
SHA256
82a71d82509198e79f801a6053f9ccfe4b2edcc3bb751fed0a12f8ec55e3d9ce
MD5
9f1e218d8676d9e9a4766e2e9d04c3d2

Сигнатуры

Execution

T1204.002 mimics_extension: Attempts to mimic the file extension

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1036 mimics_extension: Attempts to mimic the file extension
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Command and Control

T1071.001 network_http: Performs HTTP requests

Other

networkdyndns_checkip: Connects to a Dynamic DNS domain
yara_rules: Static rules
ip_domains: Identifies an IP address using external resources
creates_in_programdata: Creates files in the ProgramData directory