Managed XDR

rv_-cobro-juridico.msg — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
rv_-cobro-juridico.msg
Тип файла
CDFV2 Microsoft Outlook Message
Размер файла
2.9 MB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x64 en

Хеши

SHA1
fece4575de86c4aa22ea2d61b9e11ea37f29f223
SHA256
5d6a2160a7af5bc41acbf2099387169d9d20a1a8a1ce36f516e55610144a49be
MD5
612f2b7b1f1f08837d5b9d59b7c6e005

Сигнатуры

Execution

T1059.001 suspicious_powershell: Creates suspicious powershell process

Privilege Escalation

T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1036 copies_utilities: Copies and runs system utility with different name
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

creates_exe: Creates executable files in the file system
executes_dropped_exe: Executes dropped exe files
no_graphical_activity: No graphic activity