Managed XDR

c-users-user-appdata-l...ty-form-for-ndc-61.lnk — malware analysis report

File info

Filename
c-users-user-appdata-local-temp-ddanlywo.idj-confirmation-of-availability-form-for-ndc-61-confirmation-of-availability-form-for-ndc-61.lnk
File type
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has command line arguments, Icon, Archive, ctime=Sun Oct 1 06:49:44 2023, mtime=Thu Jul 23 18:05:09 2026, atime=Sun Oct 1 06:49:44 2023, length=245248, window=hidenormalshowminimized
File size
1.8 KB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
ae1bc9132ac7db4873727fabdd10a1e9b7b70f80
SHA256
a31b27bd8e88fb12d217c647a26488e5c3624e52c06e3bc5a9479bdc23b21132
MD5
5cea7b2245f94083d83a0574f77b6052

Signatures

Execution

T1204 suspicious_lnk: LNK file with suspicious content
T1047 antivm_wmi: Uses WMI to detect virtual environment
T1047 has_wmi: Executes one or several WMI requests

Persistence

T1574.011 persistence_services: Modifies Services registry key
T1543.003 persistence_services: Modifies Services registry key

Privilege Escalation

T1574.011 persistence_services: Modifies Services registry key
T1543.003 persistence_services: Modifies Services registry key

Defense Evasion

T1497.001 antivm_wmi: Uses WMI to detect virtual environment
T1574.011 persistence_services: Modifies Services registry key
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization

Credential Access

T1555.004 windows_credential_manager: Acquire credentials from the Windows Credential Manager

Discovery

T1497.001 antivm_wmi: Uses WMI to detect virtual environment
T1057 has_wmi: Executes one or several WMI requests
T1082 has_wmi: Executes one or several WMI requests
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization

Command and Control

T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp

Other

network_bind: Starts servers listening at None
no_graphical_activity: No graphic activity
creates_suspended_process: Creates suspended process
suspicious_network_port: Performs TCP or UDP request to non-standard port
test_check_service: Starts services
yara_rules: Static rules