Managed XDR

a6d995d015c16985b456bc...1eadc51e1d02a3c6ef.lnk — malware analysis report

File info

Filename
a6d995d015c16985b456bcc5cd44377c3e5e5cf72b17771eadc51e1d02a3c6ef.lnk
File type
MS Windows shortcut, Item id list present, Points to a file or directory, Has Description string, Has Relative path, Has Working directory, Has command line arguments, Icon number=13, Archive, ctime=Fri May 5 12:20:01 2023, mtime=Tue Feb 27 11:52:44 2024, atime=Fri May 5 12:20:01 2023, length=289792, window=hidenormalshowminimized
File size
3.3 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
efd86577edd62e058ace9644628c6715db170653
SHA256
c300749ea44f886be1887b3e19b946efbdbbc3e1bf3e416c78cfbff8d23bf70a
MD5
ce3a895eb2270dc891369cca221defef

Signatures

Execution

T1204 suspicious_lnk: LNK file with suspicious content

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
opens_document: Opens office documents
creates_doc: Creates (office) documents in the file system
unexpected_exception: Unexpected exception
create_rpc_bindings: Creates RPC connection
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object