Managed XDR

hemos-realizado-unpago...a-farmatodo.com-1-.eml — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
hemos-realizado-unpago-exitoso_tornillos-y-mangueras-tuy-2008-c.a-para_-cxpbysvenezuela-farmatodo.com-1-.eml
Тип файла
SMTP mail, ASCII text, with very long lines, with CRLF line terminators
Размер файла
174 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
bc2bba9e70a79bfdec6dbe848fd2604585c38547
SHA256
7c02bfb5762b816588cc659eed75ddb5926e2de5ec5fd8d0163110c106d5b7ce
MD5
e96a80a88666c21a44935c54c86287da

Сигнатуры

Initial Access

T1192 html_urls: HTML-document downloads a file

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Command and Control

T1102.003 references_google: Contains links to cloud services of Google (potentially for malicious payload delivery)

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
origin_langid: Unconventional language of the executable file