Managed XDR

releaseform.pdf.lnk — malware analysis report

File info

Filename
releaseform.pdf.lnk
File type
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has command line arguments, Icon number=70, Archive, ctime=Sat Sep 15 07:11:58 2018, mtime=Sat Sep 15 07:11:58 2018, atime=Sat Sep 15 07:11:58 2018, length=40960, window=hidenormalshowminimized
File size
1.1 KB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
9ad08a31258c8453c3236a3d0474cbc637f0e685
SHA256
d4d1b257b449ac4cb02b4cd74de83abb09714d71c5bf5e41bb26d176dca3731f
MD5
8f1219932acc77e61e012647ce45057f

Signatures

Execution

T1204 suspicious_lnk: LNK file with suspicious content
T1059.001 url_cmdline: Cmdline of process contains URL
T1059.003 url_cmdline: Cmdline of process contains URL

Defense Evasion

T1218 suspicious_cmdline: Executes a suspicious command
T1497.003 antisandbox_idletime: Detects Windows Idle Time to determine the uptime

Discovery

T1497.003 antisandbox_idletime: Detects Windows Idle Time to determine the uptime

Command and Control

T1071.001 network_http: Performs HTTP requests
T1071.001 wininet_https: Performs HTTP/HTTPS requests using WinInet

Other

yara_rules: Static rules
suspicious_process_network: Unusual process network activity detected
creates_suspended_process: Creates suspended process
test_check_service: Starts services