Managed XDR

c-windows-tasks-proposal.lnk — malware analysis report

File info

Filename
c-windows-tasks-proposal.lnk
File type
MS Windows shortcut, Item id list present, Has Description string, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, ctime=Thu Jan 2 13:40:40 2025, mtime=Thu Jan 2 13:40:40 2025, atime=Thu Jan 2 13:40:40 2025, length=0, window=hidenormalshowminimized
File size
1 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
43fa6567677310f13f9194be6bd24f8c15c3e730
SHA256
de721ba5569cde7c3f39f2ae29da59b6b58702e70ea4102a4bf64555f0b9939c
MD5
bc1a2372e2d9af78d2099b2cc55c1477

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.001 antivm_queries_computername: Retrieves the computer name
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antivm_queries_computername: Retrieves the computer name
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1135 server_share_info: Retrieves information about each shared resource on a server

Other

yara_rules: Static rules
creates_exe: Creates executable files in the file system
unexpected_exception: Unexpected exception
no_graphical_activity: No graphic activity
create_rpc_bindings: Creates RPC connection
creates_suspended_process: Creates suspended process
test_check_service: Starts services