Managed XDR

rundll32.lnk — malware analysis report

File info

Filename
rundll32.lnk
File type
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Archive, ctime=Mon Mar 31 15:17:55 2025, mtime=Mon Mar 31 15:17:55 2025, atime=Wed Oct 6 13:52:23 2021, length=61440, window=hide
File size
1.3 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
4dd5c354c45632db42809cd293ba76a43f7002f8
SHA256
3da68fef916c44550c2192c675b291b3c6529d5cc3258b3ebb4d8e7fb3302da9
MD5
f40ca69caab8764f02b30d4882b63b48

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
create_process_failed: Could not start the process
unexpected_exception: Unexpected exception
no_graphical_activity: No graphic activity
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object