Managed XDR

8fc47e52a2f75d2afce9a9...66edfa4a4f3c48e3b3.lnk — malware analysis report

File info

Filename
8fc47e52a2f75d2afce9a9d3972e88f0ef14ce66edfa4a4f3c48e3b3.lnk
File type
MS Windows shortcut, Item id list present, Has Relative path, Has Working directory, Has command line arguments, Archive, ctime=Mon Jan 1 00:00:00 1601, mtime=Mon Jan 1 00:00:00 1601, atime=Mon Jan 1 00:00:00 1601, length=0, window=hidenormalshowminimized
File size
1.3 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
12e2d85f34ef976eaefc19925db543fe1dbd2306
SHA256
f23c8d84e5d32575fe6f7bc0ab42b2ef4247c9726ae9c05fb7e70d2c571ccf93
MD5
ce48b0e995dfd57f552d880174197832

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object