Managed XDR

resume.pdf-.lnk.download — malware analysis report

File info

Filename
resume.pdf-.lnk.download
File type
MS Windows shortcut, Item id list present, Has Working directory, Has command line arguments, ctime=Fri Mar 21 13:19:46 2025, mtime=Fri Mar 21 13:19:46 2025, atime=Fri Mar 21 13:19:46 2025, length=0, window=hidenormalshowminimized
File size
1.3 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
d2421499aece2c3254623c9cab274b8a98d19a06
SHA256
98f3350a8303cc5adb72e4a267661bda36cf24e6865b87bccc32a4d094f5b9b3
MD5
6dffad0c0a0e8966a63a0f9a3c9bb514

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.001 antivm_disk_size: Checks the amount of free disk space
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1083 crawls_directories: Opens a huge number of directories all over disk C: (possibly, searches for sensitive data)
T1497.001 antivm_disk_size: Checks the amount of free disk space
T1518 locates_browser: Attempts to identify where browsers are installed

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
no_graphical_activity: No graphic activity
creates_suspended_process: Creates suspended process