Managed XDR

4.20241008.20250426.59...t.web.cspambo09.nm.eml — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
4.20241008.20250426.599859.24140.140401098880768.1.spamreport.web.cspambo09.nm.eml
Тип файла
HTML document, ASCII text, with CRLF line terminators
Размер файла
14.1 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
7dee1a298a4bca91949762077cbc26ef2078230d
SHA256
f5803748c52c722eeb06d6d0cde99f8d4e07913e495c50a860af6f879f500ba7
MD5
f6cdc9c5acbe9da7b85999d6b160df77

Сигнатуры

Initial Access

T1192 html_urls: HTML-document downloads a file

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
get_policy_info: Retrieves information about a Policy object