Managed XDR

bloquear-pc.lnk.infected.000.infected.000 — malware analysis report

File info

Filename
bloquear-pc.lnk.infected.000.infected.000
File type
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=272, Archive, ctime=Wed Jan 13 17:45:14 2021, mtime=Wed Apr 7 18:09:44 2021, atime=Wed Jan 13 17:45:14 2021, length=71680, window=hide
File size
1.4 KB
First seen
Last seen

Environment

w10/x86 en

Hashes

SHA1
c87fad5bf798f95ef7a83d72f1db1e6d9b159ce8
SHA256
c7d6ad5eab737186de73441f23b9c664e422eaff99ca2bd5076b33cc0425674e
MD5
da453ed41b699ef64da07dbfc14da0d8

Signatures

Execution

T1047 antivm_wmi: Uses WMI to detect virtual environment
T1047 has_wmi: Executes one or several WMI requests

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.001 antivm_generic_cpu: Checks the CPU name, possibly for anti-virtualization
T1497.001 antivm_wmi: Uses WMI to detect virtual environment
T1497.003 antisandbox_idletime: Detects Windows Idle Time to determine the uptime
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1552.002 opens_registry_hive_file: Attempts to open Windows registry hive file
T1003.002 opens_registry_hive_file: Attempts to open Windows registry hive file

Discovery

T1497.001 antivm_generic_cpu: Checks the CPU name, possibly for anti-virtualization
T1497.001 antivm_wmi: Uses WMI to detect virtual environment
T1497.003 antisandbox_idletime: Detects Windows Idle Time to determine the uptime
T1082 has_wmi: Executes one or several WMI requests

Impact

T1531 mahcine_lock: Blocks the workstation

Other

creates_in_windows: Creates files in the Windows directory
creates_exe: Creates executable files in the file system
creates_suspended_process: Creates suspended process
access_recyclebin: Manipulation with recyclebin detected
creates_in_programdata: Creates files in the ProgramData directory
test_check_service: Starts services
writes_data: Writes big amount of data to disk
yara_rules: Static rules
Managed XDR