Managed XDR

c-users-user-appdata-l...nit_curriculo_0910.lnk — malware analysis report

File info

Filename
c-users-user-appdata-local-temp-wfnxy53u.xq0-curriculo_outubro_2024_xhto3enwphibnit_curriculo_0910.lnk
File type
MS Windows shortcut, Item id list present, Has Relative path, Has command line arguments, Archive, ctime=Wed Oct 6 13:51:47 2021, mtime=Tue Nov 5 23:36:33 2024, atime=Wed Oct 6 13:51:47 2021, length=868864, window=hidenormalshowminimized
File size
2 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
0a6819fe261a3e5f3827fa846381c5c67203bf15
SHA256
4753f9564e492218913a52f0cf665484af8adbc63c462f9f3cbd4851d2e03176
MD5
fa4600c9762d1e223e1c6935d1d387b7

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
create_rpc_bindings: Creates RPC connection
creates_suspended_process: Creates suspended process