Managed XDR

readme.lnk — malware analysis report

File info

Filename
readme.lnk
File type
MS Windows shortcut, Item id list present, Has command line arguments, Icon number=1, ctime=Wed Mar 27 20:37:47 2024, mtime=Wed Mar 27 20:37:47 2024, atime=Wed Mar 27 20:37:47 2024, length=0, window=hide
File size
360 Bytes
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
9955f53e2b3775492cdc8e6e84c9a4dce91876a3
SHA256
9d88c8da2fb64005ada91df818f8aedb398b8c9eab975e9ef6f63c46d8c891cb
MD5
76260154657f139ac51ebdb355e85908

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
no_graphical_activity: No graphic activity
creates_suspended_process: Creates suspended process
message_box: Displays a message
get_policy_info: Retrieves information about a Policy object