Managed XDR

19775cf37f51c84fbe8b6681b732a60e.virus — malware analysis report

File info

Filename
19775cf37f51c84fbe8b6681b732a60e.virus
File type
MS Windows shortcut, Item id list present, Points to a file or directory, Has command line arguments, Icon number=8, Archive, ctime=Mon Dec 11 11:39:23 2023, mtime=Wed Dec 18 08:58:54 2024, atime=Mon Dec 11 11:39:23 2023, length=245248, window=hidenormalshowminimized
File size
1.7 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
4d5adfb92487688da412c779d58f693519c0e44c
SHA256
f96c59d4fc0a7cb5ee36c37a72ad84ac6cac0aea25e78569b1f3a40552354cf3
MD5
19775cf37f51c84fbe8b6681b732a60e

Signatures

Execution

T1204 suspicious_lnk: LNK file with suspicious content

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1518 locates_browser: Attempts to identify where browsers are installed

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object