Managed XDR

c10ea724383308f37510d636d4e888d9.virus — malware analysis report

File info

Filename
c10ea724383308f37510d636d4e888d9.virus
File type
MS Windows shortcut, Item id list present, Has Description string, Has Relative path, Has Working directory, Has command line arguments, Icon number=19, ctime=Wed Jan 8 12:40:16 2025, mtime=Wed Jan 8 12:40:16 2025, atime=Wed Jan 8 12:40:16 2025, length=0, window=hidenormalshowminimized
File size
668 Bytes
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
d1174b9a4e0137452f82cc827407764a0a1015f6
SHA256
111edb9083e9562cf09a4825e3f42628284ee41c726ad639e2c9b8186341aa83
MD5
c10ea724383308f37510d636d4e888d9

Signatures

Execution

T1204 suspicious_lnk: LNK file with suspicious content
T1059.001 suspicious_process: Spawns a suspicious process
T1059.001 url_cmdline: Cmdline of process contains URL
T1059.003 url_cmdline: Cmdline of process contains URL

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1218 suspicious_cmdline: Executes a suspicious command
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files

Command and Control

T1071.001 wininet_https: Performs HTTP/HTTPS requests using WinInet

Other

yara_rules: Static rules
suspicious_process_network: Unusual process network activity detected
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object