Managed XDR

_-008-notificacion-dem...plimiento-10d31db0.eml — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
_-008-notificacion-demanda-por-incumplimiento-10d31db0.eml
Тип файла
news or mail, ASCII text, with CRLF line terminators
Размер файла
66.1 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
f34a458cda4c27b7113d07d1b1b3c1a06d5adae3
SHA256
c7f73c27f4cd58ea639e17fc9db79a3922c3a7d9798218baf314c446805e040f
MD5
179d395c8aa31383500ce457df361fce

Сигнатуры

Persistence

T1574 dropper_dll: Creates DLL, which is then loaded into the process

Privilege Escalation

T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_process_token: Opens the access token associated with a process

Command and Control

T1102.003 references_google: Contains links to cloud services of Google (potentially for malicious payload delivery)

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
valid_authenticode: The digital signature has been verified
has_pdb: This executable file has a PDB path
origin_langid: Unconventional language of the executable file
pe_overlay: PE file contains overlay