Managed XDR

carved-5481860128-.lnk — malware analysis report

File info

Filename
carved-5481860128-.lnk
File type
MS Windows shortcut, Item id list present, Points to a file or directory, Archive, ctime=Wed Jul 17 15:49:29 2024, mtime=*Invalid time*, atime=Fri Jul 19 20:16:12 2024, length=14085, window=hide
File size
16 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
4bdd9943ec91aa0684b8708c5bfd68e1268e2cfa
SHA256
6f01a3d9bec8efd9772564ed367ad1cb957af970d1bb557c3969e8136e763cb2
MD5
94cae59f80a016585b7a62dd0b92f4a7

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process