Managed XDR

kingston.lnk — malware analysis report

File info

Filename
kingston.lnk
File type
MS Windows shortcut, Item id list present, Points to a file or directory, Has Description string, Has command line arguments, Icon number=79, Archive, ctime=Thu Jan 14 23:16:27 2021, mtime=Tue Sep 6 08:55:46 2022, atime=Thu Jan 14 23:16:27 2021, length=236544, window=hidenormalshowminimized
File size
3 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
184ad4a12efc735780e7f4486ee31c2fd0f448d2
SHA256
6baa4cd286cfee48fa1b66ccc4b5aa5432df1ae438ec4f1db6597eb176172998
MD5
7cb5175fb2329a1621fea8d950913ca7

Signatures

Execution

T1204 suspicious_lnk: LNK file with suspicious content

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object