Managed XDR

password.pdf.lnk — malware analysis report

File info

Filename
password.pdf.lnk
File type
MS Windows shortcut, Item id list present, Has Description string, Has Relative path, Has Working directory, Has command line arguments, Icon number=70, ctime=Mon Jan 1 00:00:00 1601, mtime=Mon Jan 1 00:00:00 1601, atime=Mon Jan 1 00:00:00 1601, length=0, window=hidenormalshowminimized
File size
2.3 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
89b6cad6c95a9b47aef6bd6f6259013ceeb33caf
SHA256
0a9a091d09096257235189cdeb5a3a0a0a86e3d29bfec12b1eae19ecd48a2f1f
MD5
d54e0fb6120a53cb1a579352a4fadec4

Signatures

Execution

T1059.001 suspicious_powershell: Creates suspicious powershell process
T1059.001 suspicious_process: Spawns a suspicious process

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object
suricata_alert: Malicious traffic detected