Managed XDR

4.20240514.20241130.65...t.web.cspambo07.nm.eml (CloudEyE) — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
4.20240514.20241130.655230.39008.140256100243200.1.spamreport.web.cspambo07.nm.eml
Тип файла
HTML document, ASCII text, with CRLF line terminators
Размер файла
17.1 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
1b6cbe5e2af960b8408ef1ce27b81942b3a07fc5
SHA256
fc783c8f85fcd84c75a12e5f401daba3b1f26a7d76543a66cc5996ed3e9780bf
MD5
1f0d8142d9b0f66263cae1a3c0fc2614

Вредоносное ПО

  • CloudEyE

Сигнатуры

Initial Access

T1192 html_urls: HTML-document downloads a file

Execution

T1059.001 suspicious_powershell: Creates suspicious powershell process
T1059.001 suspicious_process: Spawns a suspicious process
T1047 has_wmi: Executes one or several WMI requests
T1106 susp_callbacks: Suspicious usage of some WinAPI with callbacks

Privilege Escalation

T1055.012 injection_runpe: Injects code into another process
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1055 injection_failed: The attempt to inject into a process has failed

Defense Evasion

T1055.012 injection_runpe: Injects code into another process
T1027.002 guloader_behaviour: Cloudeye/GuLoader specific behaviour has been detected
T1497 antidbg_setinformationthread: Attempts to evade debugger using NtSetInformationThread
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1562 dep_disable: Disables DEP
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1070 stealth_window: A process created a hidden window
T1055 injection_failed: The attempt to inject into a process has failed

Credential Access

T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files

Discovery

T1497 antidbg_setinformationthread: Attempts to evade debugger using NtSetInformationThread
T1057 has_wmi: Executes one or several WMI requests
T1082 reads_csrss: Attempts to read csrss.exe memory

Collection

T1560.001 archive_via_utility: Detected archiving data via utility

Command and Control

T1071.001 network_http: Performs HTTP requests
T1071.001 wininet_openurl: Performs HTTP/HTTPS-requests using InternetOpenUrl

Other

suricata_alert: Malicious traffic detected
unpacker_wrong_base: Possibly, an error occured in the file unpacker
unexpected_exception: Unexpected exception
no_graphical_activity: No graphic activity
create_rpc_bindings: Creates RPC connection
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object
checktokenmembership: Checks user token with CheckTokenMembership call
yara_rules: Static rules

Похожие отчёты