Managed XDR

.lnk — malware analysis report

File info

Filename
.lnk
File type
MS Windows shortcut, Item id list present, Points to a file or directory, Has command line arguments, Icon number=8, Archive, ctime=Mon Dec 4 02:45:36 2023, mtime=Sat Sep 20 16:36:54 2025, atime=Mon Dec 4 02:45:36 2023, length=236544, window=hidenormalshowminimized
File size
1.7 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
12aa012071bc708191599fbc644859fd5149bc7d
SHA256
f95a075ce6edb8c03d95ba8e7e6aed0aa22b1b1902dcd9a0cfb3dbe393bad346
MD5
bf675ddd1e2bb4f583673e8968e750c3

Signatures

Execution

T1204 suspicious_lnk: LNK file with suspicious content

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1518 locates_browser: Attempts to identify where browsers are installed

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object
suricata_alert: Malicious traffic detected