Managed XDR

mypic.lnk — malware analysis report

File info

Filename
mypic.lnk
File type
MS Windows shortcut, Item id list present, Has Description string, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, ctime=Mon Jan 1 00:00:00 1601, mtime=Mon Jan 1 00:00:00 1601, atime=Mon Jan 1 00:00:00 1601, length=0, window=hidenormalshowminimized
File size
2.1 KB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
387f907514186d63ba432f29836f30a301898d9f
SHA256
94c31325660dcddf5c3a7ac55e24e24c9d3714dbd4a1394fc80e08d5815bfb7c
MD5
95bf1a24e2c57bcda9879bb742f04fd9

Signatures

Execution

T1059.001 suspicious_powershell: Creates suspicious powershell process
T1059.001 suspicious_process: Spawns a suspicious process

Defense Evasion

T1497.003 antisandbox_idletime: Detects Windows Idle Time to determine the uptime

Discovery

T1497.003 antisandbox_idletime: Detects Windows Idle Time to determine the uptime
T1518 locates_browser: Attempts to identify where browsers are installed

Other

dns_without_resolve: DNS query without a response
dead_host: Connects to IP addresses that do not respond to requests
dead_host_suspicious: Connects to IP addresses with suspicious port that do not respond (possible Meterpreter)
no_graphical_activity: No graphic activity
creates_suspended_process: Creates suspended process
test_check_service: Starts services
yara_rules: Static rules