Managed XDR

c-users-user-appdata-l...-hqr402ke.0wd-.pdf.lnk — malware analysis report

File info

Filename
c-users-user-appdata-local-temp-hqr402ke.0wd-.pdf.lnk
File type
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has command line arguments, Icon number=0, Archive, ctime=Fri Sep 6 09:05:48 2024, mtime=Wed Oct 23 02:57:43 2024, atime=Fri Sep 6 09:05:48 2024, length=89600, window=hide
File size
86.5 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
a6a29946269107b9fd3bcd85386ef9d7438b7ae1
SHA256
3b88b3efbdc86383ee9738c92026b8931ce1c13cd75cd1cda2fa302791c2c4fb
MD5
65da1a9026cf171a5a7779bc5ee45fb1

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1036 rundll_suspicious_extension: Runs rundll32, submitting a file with a suspicious extension
T1218.011 rundll_suspicious_extension: Runs rundll32, submitting a file with a suspicious extension
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1518 locates_browser: Attempts to identify where browsers are installed

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
no_graphical_activity: No graphic activity
creates_suspended_process: Creates suspended process
message_box: Displays a message
get_policy_info: Retrieves information about a Policy object