Managed XDR

thaytet-t-to-ph-1-2-it-iteasoi.docx.lnk — malware analysis report

File info

Filename
thaytet-t-to-ph-1-2-it-iteasoi.docx.lnk
File type
MS Windows shortcut, Item id list present, Points to a file or directory, Has command line arguments, Icon number=0, Archive, ctime=Thu Aug 22 10:03:32 2013, mtime=Thu Aug 22 10:03:32 2013, atime=Thu Aug 22 10:03:31 2013, length=355840, window=hidenormalshowminimized
File size
399.6 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
fdb52564ee5cf7ecbcd6198da2c14b6b757cce75
SHA256
14877c9ddf4d0f905c66b88ba48d05f9c094d8c6c2497da2d92323289b42a621
MD5
5f5be55adc971381f4e02203b7b532cc

Signatures

Execution

T1059.001 suspicious_powershell: Creates suspicious powershell process
T1204 suspicious_lnk: LNK file with suspicious content
T1059.007 bad_js: Suspicious Javascript file
T1059.001 suspicious_process: Spawns a suspicious process
T1059 wscript_info_discovery: Collects info about system with Wscript.Shell

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1112 creates_largekey: Saves very large data in the registry, can be used to save the configuration or body of the malware
T1140 unpacking_utilities: Uses Windows utilities to unpack data
T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1070.004 self_removal_command: Executes command to delete itself

Credential Access

T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files

Discovery

T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1083 checks_recent_files: Attempt to check recently opened files through registry
T1033 wscript_info_discovery: Collects info about system with Wscript.Shell

Other

yara_rules: Static rules
creates_exe: Creates executable files in the file system
creates_in_windows: Creates files in the Windows directory
opens_document: Opens office documents
creates_doc: Creates (office) documents in the file system
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
break_limit_exceeded: Warning: function calls limit has been exceeded
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services