Managed XDR

proposal.lnk — malware analysis report

File info

Filename
proposal.lnk
File type
MS Windows shortcut, Item id list present, Has Description string, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, ctime=Thu Jan 2 13:40:40 2025, mtime=Thu Jan 2 13:40:40 2025, atime=Thu Jan 2 13:40:40 2025, length=0, window=hidenormalshowminimized
File size
3.4 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
1aaa36ad7254a084e476dba34b95834f460ff16f
SHA256
11f1ebc8d4e7f3ac9b137343da1d80595e77a90a6c7e8bb81e447773873fa10b
MD5
f27df6b5370eb52b64421f24aca95c4e

Signatures

Execution

T1204 suspicious_lnk: LNK file with suspicious content

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.001 antivm_disk_size: Checks the amount of free disk space
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1552 infostealer_browser: Retrieves personal information from local Internet browsers
T1503 infostealer_browser: Retrieves personal information from local Internet browsers
T1552 infostealer_mail: Collects personal data from local email clients
T1552 cookie_files: Accesses cookie files
T1555.003 cookie_files: Accesses cookie files
T1555.004 windows_credential_manager: Acquire credentials from the Windows Credential Manager

Discovery

T1497.001 antivm_disk_size: Checks the amount of free disk space
T1083 crawls_directories: Opens a huge number of directories all over disk C: (possibly, searches for sensitive data)
T1518 locates_browser: Attempts to identify where browsers are installed

Collection

T1114 infostealer_mail: Collects personal data from local email clients

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process