Managed XDR

test-email-with-file-t...nown_malicious.exe.eml — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
test-email-with-file-test_unknown_malicious.exe.eml
Тип файла
ASCII text, with very long lines, with CRLF line terminators
Размер файла
9 MB
Первое обнаружение
Последнее обнаружение

Окружение

w10/x64 en

Хеши

SHA1
c446ce850d9a432b12f189b12407146db135d970
SHA256
10b6d798e69efcf389e23c1de51df551939a8c451fa26f7d21fab7498cf1b30f
MD5
256a0255717421819ed97e244a6e61ac

Сигнатуры

Execution

T1047 has_wmi: Executes one or several WMI requests
T1059.006 drops_python_dll: Drops python dll

Persistence

T1574 dropper_dll: Creates DLL, which is then loaded into the process

Privilege Escalation

T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Impact

T1490 vssadmin_delete_shadows: Attempt to delete volume shadow copies
T1490 wbadmin_delete_backup: Removes system backup copies using wbadmin utility
T1489 net_stop: Stops services through the use of net stop

Other

ransomware_shadowcopy: Removes volume shadow copies
creates_exe: Creates executable files in the file system
no_graphical_activity: No graphic activity
creates_suspended_process: Creates suspended process
test_check_service: Starts services
pe_overlay: PE file contains overlay
yara_rules: Static rules