Managed XDR

c-recycle.bin-s-1-5-21...ndto-fax-recipient.lnk — malware analysis report

File info

Filename
c-recycle.bin-s-1-5-21-2728444500-1079535748-4130302051-500-rape061.user-appdata-roaming-microsoft-windows-sendto-fax-recipient.lnk
File type
MS Windows shortcut, Has Description string, Has Relative path, Has command line arguments, Icon number=0, Archive, ctime=Tue Jul 14 00:36:26 2009, mtime=Tue Jul 14 00:36:26 2009, atime=Tue Jul 14 01:39:52 2009, length=974336, window=hide
File size
225.2 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
f3c1de9463c77f0bd19c014333b1c0f334ca6cca
SHA256
3f4481c1f4cdbb98d0f124446055b8066b19727cffe7eafe0730137d079e6fb3
MD5
87de0032dda030cc358fb6ddfb80736e

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1096 persistence_ads: Creates Alternate Data Stream (ADS)
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object
creates_in_programdata: Creates files in the ProgramData directory
test_check_service: Starts services