Managed XDR

invitation-to-the-inte...summit-5-may-2025..eml (TONESHELL) — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
invitation-to-the-inter-agency-meeting-for-the-46th-asean-summit-2nd-asean-gcc-summit-and-asean-gcc-china-summit-5-may-2025..eml
Тип файла
SMTP mail, ASCII text, with CRLF line terminators
Размер файла
12.6 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
628d227d88ce9199f1c2001750b67301224f1c3a
SHA256
122129505b95b093a0dc313177496372b468edc1a84a628b5fe311a45143a95e
MD5
884f9b8f7738b6ba82dc4cf4200e5795

Вредоносное ПО

  • TONESHELL

Сигнатуры

Execution

T1053.005 creates_tasks: Creates a delayed task using Task Scheduler
T1053.005 persistence_autorun: Makes itself run automatically on Windows startup

Persistence

T1053.005 creates_tasks: Creates a delayed task using Task Scheduler
T1053.005 persistence_autorun: Makes itself run automatically on Windows startup
T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1574 dropper_dll: Creates DLL, which is then loaded into the process

Privilege Escalation

T1053.005 creates_tasks: Creates a delayed task using Task Scheduler
T1053.005 persistence_autorun: Makes itself run automatically on Windows startup
T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1574 dropper_dll: Creates DLL, which is then loaded into the process

Defense Evasion

T1070.004 deletes_self: Moves to different location or removes the original executable file
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1497.001 antivm_queries_computername: Retrieves the computer name
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antivm_queries_computername: Retrieves the computer name

Command and Control

T1102.003 references_google: Contains links to cloud services of Google (potentially for malicious payload delivery)

Other

suricata_alert: Malicious traffic detected
no_graphical_activity: No graphic activity
valid_authenticode: The digital signature has been verified
has_pdb: This executable file has a PDB path
creates_suspended_process: Creates suspended process
message_box: Displays a message
creates_in_programdata: Creates files in the ProgramData directory
pe_overlay: PE file contains overlay