Managed XDR

temp-100-.eml (STRRAT) — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
temp-100-.eml
Тип файла
RFC 822 mail, UTF-8 Unicode text, with CRLF line terminators
Размер файла
642.4 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
b851ca3415ab87d560b21c7a9d443a1daaceaf4f
SHA256
d7709e9576d8e5d35e52875942c6af30985e334bdf58269880eef1bcbea4cff4
MD5
f5bd4a3ce09aff63c23b3f54380bc90b

Вредоносное ПО

  • STRRAT

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Command and Control

T1102.003 cloud_github: Connects to cloud services of Github (potentially for malicious payload delivery)

Other

yara_rules: Static rules
creates_in_programdata: Creates files in the ProgramData directory

Похожие отчёты