Managed XDR

529494f740518324e4b93e48673c8b69.virus — malware analysis report

File info

Filename
529494f740518324e4b93e48673c8b69.virus
File type
MS Windows shortcut, Item id list present, Points to a file or directory, Has command line arguments, Icon number=8, Archive, ctime=Fri Nov 17 05:59:51 2023, mtime=Sat Nov 18 11:47:07 2023, atime=Fri Nov 17 05:59:51 2023, length=236544, window=hidenormalshowminimized
File size
1.7 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
496ece48530993162fa4706f5bfe66a71a38fb1e
SHA256
204550cc37d23812c85bb3f36871983b155805f203edf0d76adb682374b21119
MD5
529494f740518324e4b93e48673c8b69

Signatures

Execution

T1204 suspicious_lnk: LNK file with suspicious content

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1518 locates_browser: Attempts to identify where browsers are installed

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object