Managed XDR

example.lnk — malware analysis report

File info

Filename
example.lnk
File type
MS Windows shortcut, Item id list present, Has Description string, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, ctime=Tue Mar 4 17:29:30 2025, mtime=Tue Mar 4 17:29:30 2025, atime=Tue Mar 4 17:29:30 2025, length=0, window=hidenormalshowminimized
File size
4.6 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
18389b35c83d1b817a70de4954a03752e82f3192
SHA256
742a1da20faf007614deab4aef724ea6de7079fc731a534d9f5f457cccba500c
MD5
573553079558edf5228476e19cf37ff6

Signatures

Execution

T1059.001 suspicious_powershell: Creates suspicious powershell process
T1059.001 suspicious_process: Spawns a suspicious process

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

unexpected_exception: Unexpected exception
no_graphical_activity: No graphic activity
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object
yara_rules: Static rules