Managed XDR

photov_324438698734.lnk — malware analysis report

File info

Filename
photov_324438698734.lnk
File type
MS Windows shortcut, Has command line arguments, Icon, ctime=Wed May 29 15:15:48 2024, mtime=Mon Dec 30 12:44:53 2024, atime=Sun Sep 28 08:25:09 2025, length=504883, window=hidenormalshowminimized
File size
2.6 KB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
6ff2be453f66a7d84eb21d29f12724ebdc8fc9a9
SHA256
e0946743d13cc3a65fb991bcd756a8b26932a4beccdb1155139b9cd82cfff4a5
MD5
51d423c8e3276836ea10abec984b254e

Signatures

Execution

T1059.001 suspicious_powershell: Creates suspicious PowerShell process
T1059.001 suspicious_process: Spawns a suspicious process
T1047 antivm_wmi: Uses WMI to detect virtual environment
T1047 has_wmi: Executes one or several WMI requests

Defense Evasion

T1497.001 antivm_wmi: Uses WMI to detect virtual environment
T1497.003 antisandbox_idletime: Detects Windows Idle Time to determine the uptime
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization

Discovery

T1497.001 antivm_wmi: Uses WMI to detect virtual environment
T1497.003 antisandbox_idletime: Detects Windows Idle Time to determine the uptime
T1082 has_wmi: Executes one or several WMI requests
T1518 locates_browser: Attempts to identify where browsers are installed
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization

Command and Control

T1071.001 network_http: Performs HTTP requests

Other

network_powershell: PowerShell process network connection detected
no_graphical_activity: No graphic activity
creates_suspended_process: Creates suspended process
suspicious_network_port: Performs TCP or UDP request to non-standard port
yara_rules: Static rules