Managed XDR

invoice.pdf.lnk — malware analysis report

File info

Filename
invoice.pdf.lnk
File type
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Wed Nov 15 02:24:28 2023, mtime=Mon Aug 12 19:25:39 2024, atime=Wed Nov 15 02:24:28 2023, length=32768, window=hide
File size
1.8 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
51031eb53eb8f95fdb02691e0844bc0633c69cd9
SHA256
4fc5f055261643a25acf22b36c9030562a211db2e2493a6d20170f6f3b6def66
MD5
d2e85b1596c0ca32cc038173843dc5a9

Signatures

Execution

T1059.005 mshta_vbscript: Runs VBScript using mshta
T1059.003 suspicious_process: Spawns a suspicious process

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1218.005 mshta_vbscript: Runs VBScript using mshta
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object