Managed XDR

win.lnk — malware analysis report

File info

Filename
win.lnk
File type
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Hidden, ctime=Fri Apr 19 06:13:07 2024, mtime=Fri Apr 19 06:13:11 2024, atime=Fri Apr 19 06:13:07 2024, length=571812, window=hideshowminimized
File size
860 Bytes
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
2e576b40be8c91bd205ef5a0a06fbec8b3463d0c
SHA256
afc428af77be4a64909e7e3901b6dac6ba5e87ae7596af257e0eb1ca4d026aa1
MD5
f5552772e483e302ada1750c6f6bedd1

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
create_process_failed: Could not start the process
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object