Managed XDR

_____spam_____-rv_-pedido-mextlan.msg — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
_____spam_____-rv_-pedido-mextlan.msg
Тип файла
CDFV2 Microsoft Outlook Message
Размер файла
911.5 KB
Первое обнаружение
Последнее обнаружение

Окружение

w10/x64 en

Хеши

SHA1
01864f12ea7c570f8b1f89a4a23a2f0749020235
SHA256
d6133b4e05917d8c67fca672bfca1ed72ee26318f7f840f5d8a2224609a93545
MD5
35da337fcfd773e84dc357d73e5f0993

Сигнатуры

Execution

T1059.001 suspicious_powershell: Creates suspicious powershell process
T1047 has_wmi: Executes one or several WMI requests

Privilege Escalation

T1055.002 inject_write_pe: Writes PE file to another process's memory
T1055.012 injection_runpe: Injects code into another process
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1055.002 inject_write_pe: Writes PE file to another process's memory
T1055.012 injection_runpe: Injects code into another process
T1562 disables_uac: Disable UAC
T1027.004 compiles_code: Compiles VB.NET code
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1562.001 windows_defender_add_exclusion: Adds a path to Microsoft Defender exclusion list

Discovery

T1518 locates_browser: Attempts to identify where browsers are installed

Other

unpacker_wrong_base: Possibly, an error occured in the file unpacker
pe_in_bcryptdecrypt: PE found in BCryptDecrypt function
runs_utility_without_cmdline: Runs system utility without arguments (non-typical usage)
process_crashed: One of the processes has failed
no_graphical_activity: No graphic activity
create_rpc_bindings: Creates RPC connection
creates_suspended_process: Creates suspended process
pe_overlay: PE file contains overlay
yara_rules: Static rules