Managed XDR

c-recycle.bin-s-1-5-21...er-links-downloads.lnk — malware analysis report

File info

Filename
c-recycle.bin-s-1-5-21-2728444500-1079535748-4130302051-500-rape061.user-links-downloads.lnk
File type
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Read-Only, Directory, ctime=Mon May 13 22:32:50 2019, mtime=Mon May 13 22:33:02 2019, atime=Mon May 13 22:33:05 2019, length=0, window=hide
File size
224.9 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
a62893b66b87b9ebd4e1dfffe2c65005ca8d8298
SHA256
a263b15d634f458f4aa79fb768c9787084a656f3e59189628674a85437a60db6
MD5
00ab536fea2b228e005106138086bde8

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.003 antisandbox_sleep: The process attempted to slow down analysis

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
test_check_service: Starts services