Managed XDR

c-users-user-appdata-l...evhk.g2z-2025-.pdf.lnk — malware analysis report

File info

Filename
c-users-user-appdata-local-temp-4e1pevhk.g2z-2025-.pdf.lnk
File type
MS Windows shortcut, Has Description string, Has command line arguments, Icon number=0, ctime=Mon Jan 1 00:00:00 1601, mtime=Mon Jan 1 00:00:00 1601, atime=Mon Jan 1 00:00:00 1601, length=0, window=hidenormalshowminimized
File size
5.5 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
3872ff7378ab6b155c9af26285f1a9ff9d496f76
SHA256
d0544a045aae0e316380b57a7319ec54f7f0979a7882f33a15839311c7e29888
MD5
ec6842538f6166462d498279b8a462b3

Signatures

Execution

T1204 suspicious_lnk: LNK file with suspicious content
T1053.005 persistence_autorun: Makes itself run automatically on Windows startup
T1059.001 url_cmdline: Cmdline of process contains URL
T1059.003 url_cmdline: Cmdline of process contains URL

Persistence

T1053.005 persistence_autorun: Makes itself run automatically on Windows startup

Privilege Escalation

T1053.005 persistence_autorun: Makes itself run automatically on Windows startup
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1218 suspicious_cmdline: Executes a suspicious command
T1126 disconnects_mapped_device: Removes network share connection
T1070.004 self_removal_command: Executes command to delete itself
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Command and Control

T1105 cmdline_curl: Uses curl utility for network data transferring

Other

unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object