Managed XDR

sample-404.eml — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
sample-404.eml
Тип файла
SMTP mail, ASCII text, with very long lines, with CRLF line terminators
Размер файла
228.5 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
70b55071454d880da19a1f6d372da7b354d03afd
SHA256
dc09d68d642aba43b6c4775fcccb0410e72f6a17b1dc5cc66afc446edd808607
MD5
e8d0886af48e6e241c2756202e7ebb76

Сигнатуры

Initial Access

T1192 html_urls: HTML-document downloads a file

Execution

T1059.001 url_cmdline: Cmdline of process contains URL
T1059.003 url_cmdline: Cmdline of process contains URL

Persistence

T1197 bitsadmin_download: Downloads a file using bitsadmin

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1197 bitsadmin_download: Downloads a file using bitsadmin
T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1070 stealth_window: A process created a hidden window
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Command and Control

T1071.001 network_http: Performs HTTP requests

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
message_box: Displays a message
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
checktokenmembership: Checks user token with CheckTokenMembership call