Managed XDR

20250621_fp_100_12.eml — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
20250621_fp_100_12.eml
Тип файла
SMTP mail, ASCII text, with very long lines
Размер файла
5.6 MB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
68a104cd5ea434f09e27a3aa09165ce13bcba5cc
SHA256
42212479c8aff6ef125664756cac3d47a203182ea98cae13da58302bbea4b250
MD5
7b102fbb7c99538096e3fa3447c47451

Сигнатуры

Execution

T1106 susp_callbacks: Suspicious usage of some WinAPI with callbacks

Persistence

T1574 dropper_dll: Creates DLL, which is then loaded into the process

Privilege Escalation

T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_enigma: Enigma protector indicators detected
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antivm_queries_computername: Retrieves the computer name
T1135 server_share_info: Retrieves information about each shared resource on a server

Other

yara_rules: Static rules
static_pe_duplicate_sections: The PE file structure contains anomalies: duplicate section names
create_rpc_bindings: Creates RPC connection
has_pdb: This executable file has a PDB path
origin_langid: Unconventional language of the executable file