Managed XDR

c-users-user-appdata-l...al-temp-office-365.lnk — malware analysis report

File info

Filename
c-users-user-appdata-local-temp-office-365.lnk
File type
MS Windows shortcut, Item id list present, Has Description string, Has Relative path, Has command line arguments, ctime=Mon Jan 1 00:00:00 1601, mtime=Mon Jan 1 00:00:00 1601, atime=Mon Jan 1 00:00:00 1601, length=0, window=
File size
866 Bytes
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
3027f78d66dca949e0d39d38ac2f70e0a1c7a8d4
SHA256
576b8ca76393baffc6355aab34903cbd369849ad7be856cbb76b6b31143426ca
MD5
6d4ded15b923ec132118f18826ffa249

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object
regsvr_scriptlet_ex: Uses regsvr32 for scriptlet execution, perhaps for AWL bypass