Managed XDR

temp_1760373502916_z5p...t18_38_31-08_00-1-.eml — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
temp_1760373502916_z5pr02-no-subject-2025-09-25t18_38_31-08_00-1-.eml
Тип файла
ASCII text, with CRLF line terminators
Размер файла
10.1 MB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
0c021f5dfcc3a22f0824326288d177d9d563adba
SHA256
e15ed8efd804711dcdcf7f4142d2dbb86d44431789d24f4f749e7aba2ab7d3c7
MD5
1f9e516b1755297ec67c1833a78a8271

Сигнатуры

Initial Access

T1192 html_urls: HTML-document downloads a file

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_upx: The executable file is compressed using UPX
T1497.001 antivm_network_adapters: Checks NIC addresses
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1027.002 packer_entropy: Probably contains compressed or encrypted data

Discovery

T1497.001 antivm_network_adapters: Checks NIC addresses

Command and Control

T1102.003 references_github: Contains links to cloud services of Github (potentially for malicious payload delivery)

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity