Managed XDR

c0r9433t129479872.eml — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
c0r9433t129479872.eml
Тип файла
SMTP mail, ASCII text, with very long lines
Размер файла
1.3 MB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
f2c4da74c213bc64fe0eebcb367a9c7796a2883e
SHA256
bf1a58b4721bc7e7321e9d40327afff43806ea37d93740843d05adf66294a319
MD5
3d217373c9c4ea4aa9c553e34311c5e9

Сигнатуры

Execution

T1059.007 bad_js: Suspicious Javascript file
T1204.002 mimics_extension: Attempts to mimic the file extension

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1036 mimics_extension: Attempts to mimic the file extension
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Discovery

T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
message_box: Displays a message
error_drawtext: An error occured while executing the file
checktokenmembership: Checks user token with CheckTokenMembership call
Managed XDR