Managed XDR

c-users-user-appdata-l..._sverki-04.25.docx.lnk — malware analysis report

File info

Filename
c-users-user-appdata-local-temp-ucgiznzg.j4n-diadoc_akt_sverki-04.25.docx.lnk
File type
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=1, Archive, ctime=Fri Feb 28 10:21:37 2025, mtime=Wed Apr 2 23:00:00 2025, atime=Fri Feb 28 10:21:12 2025, length=0, window=hidenormalshowminimized
File size
544 Bytes
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
8a7573e6db57f6b1dd57a6e7118bcdb1f952c506
SHA256
91834c3c11d6b48dab2938d347907d8ef8d0353092e0a32494875e50b100dc7d
MD5
b539c97c7ccbe6a295b2e4f9673a8cf8

Signatures

Execution

T1204 suspicious_lnk: LNK file with suspicious content
T1204.002 office_vb_load: Microsoft Office is loading VB DLL files (macros usage indicator)
T1204.002 mimics_extension: Attempts to mimic the file extension

Persistence

T1547.009 suspicious_desktop_ini: Creates desktop.ini file with suspicious content

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1547.009 suspicious_desktop_ini: Creates desktop.ini file with suspicious content

Defense Evasion

T1497.001 antivm_generic_cpu: Checks the CPU name, possibly for anti-virtualization
T1096 persistence_ads: Creates Alternate Data Stream (ADS)
T1564.001 stealth_file: Creates hidden or system files
T1497.003 antisandbox_idletime: Detects Windows Idle Time to determine the uptime
T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1036 mimics_extension: Attempts to mimic the file extension

Credential Access

T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files

Discovery

T1497.001 antivm_generic_cpu: Checks the CPU name, possibly for anti-virtualization
T1497.003 antisandbox_idletime: Detects Windows Idle Time to determine the uptime
T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents

Command and Control

T1071 network_irc: Connects to the IRC server, probably a botnet part
T1071.001 network_http: Performs HTTP requests
T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp

Other

opens_document: Opens office documents
creates_exe: Creates executable files in the file system
creates_doc: Creates (office) documents in the file system
unexpected_exception: Unexpected exception
network_ftp: Performs FTP requests
create_rpc_bindings: Creates RPC connection
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
yara_rules: Static rules