Managed XDR

curriculosmeus_2410_02...1n_october_2410_02.lnk — malware analysis report

File info

Filename
curriculosmeus_2410_02_imnii8dgv5und1n_october_2410_02.lnk
File type
MS Windows shortcut, Item id list present, Has command line arguments, Archive, ctime=Mon Jan 1 00:00:00 1601, mtime=Mon Jan 1 00:00:00 1601, atime=Mon Jan 1 00:00:00 1601, length=0, window=hidenormalshowminimized
File size
37.6 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
dacb6f147bc064cdd7e322bb8c893bb6e26ae6e2
SHA256
76664854c2a569c5d8007fffcde32fd65a07e50dfa05dd688f6a4b61b916cab2
MD5
76f0c964a2b440e5182f19a3f0bd725d

Signatures

Execution

T1059.007 mshta_javascript: Runs JavaScript using mshta

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
creates_exe: Creates executable files in the file system
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object