Managed XDR

c-users-user-appdata-l...cdj.vsk-67df4758b8.lnk — malware analysis report

File info

Filename
c-users-user-appdata-local-temp-quv34cdj.vsk-67df4758b8.lnk
File type
MS Windows shortcut, Item id list present, Points to a file or directory, Has Description string, Has Relative path, Has Working directory, Has command line arguments, Icon number=21, Archive, ctime=Wed Sep 10 01:42:07 2025, mtime=Thu Oct 9 14:00:19 2025, atime=Wed Sep 10 01:42:07 2025, length=344064, window=hidenormalshowminimized
File size
2.5 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
f0108531362ff557483fec7345dcde96679a7735
SHA256
17542f18a9e1e1f9b6cc45e1f13f0248a243207d76e66d141f1390ccd97db793
MD5
1ff350f55574afb4653f046e8f1e8470

Signatures

Execution

T1204 suspicious_lnk: LNK file with suspicious content
T1059.007 mshta_javascript: Runs JavaScript using mshta
T1059.003 suspicious_process: Spawns a suspicious process

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object