Managed XDR

cd38d6f955982a3ce574d4...9592025060f055f052.eml — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
cd38d6f955982a3ce574d4e911c636eba024da426f57799592025060f055f052.eml
Тип файла
ASCII text, with very long lines, with CRLF line terminators
Размер файла
753.4 KB
Первое обнаружение
Последнее обнаружение

Окружение

w10/x64 en

Хеши

SHA1
745ec7ba14e27340898ead20d994bb9e2aaa495a
SHA256
7263661a6e3c44fcb235b8e270463c5922b9eeb33a8c36143e48d283d789102a
MD5
bfd76e2f5d52e97f2da1ba6432cca2ad

Сигнатуры

Execution

T1059.001 suspicious_powershell: Creates suspicious powershell process
T1059 powershell_cmd_longcommandline: Suspiciously long commandline
T1204.002 mimics_extension: Attempts to mimic the file extension
T1059.001 suspicious_process: Spawns a suspicious process
T1059.003 suspicious_batch: Suspicious batch

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1036 mimics_extension: Attempts to mimic the file extension
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1518 locates_browser: Attempts to identify where browsers are installed

Other

creates_suspended_process: Creates suspended process
test_check_service: Starts services