Managed XDR

cmd.exe.lnk — malware analysis report

File info

Filename
cmd.exe.lnk
File type
MS Windows shortcut, Item id list present, Points to a file or directory, Has Working directory, Has command line arguments, Archive, ctime=Wed Nov 15 20:38:31 2023, mtime=Mon Mar 25 00:57:40 2024, atime=Wed Nov 15 20:38:31 2023, length=289792, window=hide
File size
1.5 KB
First seen
Last seen

Environment

w10/x86 en

Hashes

SHA1
21d8c21cea7b0bfcc9f26d54387005d012add710
SHA256
21e693b48a6626eb26d4dd2753e34579d26666cbe8d480480ba27ee612da3e71
MD5
2f5031dc6a91258541842bdb6c32e6be

Signatures

Execution

T1204 suspicious_lnk: LNK file with suspicious content
T1059.003 executes_dropped_cmd: Executes dropped batch files

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1518 locates_browser: Attempts to identify where browsers are installed

Command and Control

T1071.001 network_http: Performs HTTP requests
T1105 cmdline_curl: Uses curl utility for network data transferring
T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp

Other

creates_in_windows: Creates files in the Windows directory
creates_exe: Creates executable files in the file system
suspicious_process_network: Unusual process network activity detected
creates_suspended_process: Creates suspended process
yara_rules: Static rules