Managed XDR

bony.lnk — malware analysis report

File info

Filename
bony.lnk
File type
MS Windows shortcut, Item id list present, Points to a file or directory, Has Description string, Has Relative path, Has command line arguments, Icon number=79, Archive, ctime=Sun Apr 21 20:13:41 2024, mtime=Sat Feb 15 19:00:21 2025, atime=Sun Apr 21 20:13:42 2024, length=236544, window=hidenormalshowminimized
File size
2.2 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
4eff1dc69b1825e2d33985d6663c3ec60bd86f17
SHA256
8ef72a59064217bdd0909a307c5e15eea99362b19607ed772c220ff6daec1c70
MD5
48a2222bdc9e121190c7df00b8ab1980

Signatures

Execution

T1204 suspicious_lnk: LNK file with suspicious content

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object