Managed XDR

bank.lnk — malware analysis report

File info

Filename
bank.lnk
File type
MS Windows shortcut, Item id list present, Points to a file or directory, Has command line arguments, Icon number=4, Archive, ctime=Wed Feb 14 07:32:23 2024, mtime=Mon Aug 26 13:33:09 2024, atime=Wed Feb 14 07:32:23 2024, length=455680, window=hide
File size
2 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
37c5f3b2f66bb1799917e727984b2ab7fad3a59b
SHA256
36fa15b01cbbb69c0f996e9a276829c2b6be46ff7c5a121dcc8a8d22b4bfa83e
MD5
1b6a2fbbf16a1aeeb37bb2fa2ffcde89

Signatures

Execution

T1059.001 suspicious_powershell: Creates suspicious powershell process
T1059.001 suspicious_process: Spawns a suspicious process

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object