Managed XDR

datev-rechnung-20nr.-2053511122025.pdf.lnk — malware analysis report

File info

Filename
datev-rechnung-20nr.-2053511122025.pdf.lnk
File type
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=11, Archive, ctime=Wed Jul 9 17:34:51 2025, mtime=Wed Jul 9 17:34:51 2025, atime=Wed Jul 9 17:34:51 2025, length=335872, window=hidenormalshowminimized
File size
1.4 KB
First seen
Last seen

Environment

win7/x64 en

Hashes

SHA1
cd3e68fac25ff339098c69d6a040b2e03496ef3f
SHA256
c92470053359e75036e53bae66d7179d858ed77c41a62c4f4b04321d67134fe6
MD5
e2bc62124bcde30c72df5c068295b3e6

Signatures

Execution

T1204 suspicious_lnk: LNK file with suspicious content
T1059.001 url_cmdline: Cmdline of process contains URL
T1059.003 url_cmdline: Cmdline of process contains URL

Persistence

T1197 bitsadmin_download: Downloads a file using bitsadmin

Defense Evasion

T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1197 bitsadmin_download: Downloads a file using bitsadmin

Command and Control

T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp

Other

unexpected_exception: Unexpected exception
no_graphical_activity: No graphic activity
creates_suspended_process: Creates suspended process
suricata_alert: Malicious traffic detected
yara_rules: Static rules
Managed XDR