Managed XDR

cpllnk.a-in-file-copy-...d-open-by-explorer.exe — malware analysis report

File info

Filename
cpllnk.a-in-file-copy-of-shortcut-to-4-.lnk-during-attempted-open-by-explorer.exe
File type
MS Windows shortcut, Item id list present, ctime=Mon Dec 23 04:07:01 2024, mtime=Mon Dec 23 04:07:01 2024, atime=Mon Dec 23 04:07:01 2024, length=0, window=hide
File size
866 Bytes
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
7022b691c4842e6c18743022a7b3208e1d730845
SHA256
cf983d200d8b7e1f9d66f2f00763c62f0deef2dec691a1cba211995d74859be3
MD5
1039f1066e28a6bcfef183f5cc9a1423

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process