Managed XDR

2024-08-05_09-01-06_winscan_to_pdf.pdf.lnk — malware analysis report

File info

Filename
2024-08-05_09-01-06_winscan_to_pdf.pdf.lnk
File type
MS Windows shortcut, Item id list present, Has Description string, Has Working directory, Has command line arguments, Icon number=13, ctime=Tue Aug 6 12:08:52 2024, mtime=Tue Aug 6 12:08:52 2024, atime=Tue Aug 6 12:08:52 2024, length=0, window=hidenormalshowminimized
File size
935 Bytes
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
d956cdc066be3d5b6472c048b1888fe07d4588c2
SHA256
2cc62e6bdc66384585f03883f21087f4e8b315a749e31818781bd1169658babf
MD5
8f40d72c89542af3fd00d3795e9fbe74

Signatures

Execution

T1204 suspicious_lnk: LNK file with suspicious content

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.001 antivm_disk_size: Checks the amount of free disk space
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antivm_disk_size: Checks the amount of free disk space

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
no_graphical_activity: No graphic activity
creates_suspended_process: Creates suspended process