Managed XDR

usb.lnk — malware analysis report

File info

Filename
usb.lnk
File type
MS Windows shortcut, Item id list present, Points to a file or directory, Has Description string, Has command line arguments, Icon number=-166, Archive, ctime=Sat Jul 16 11:43:01 2016, mtime=Sat Jul 16 11:43:01 2016, atime=Sat Jul 16 11:43:01 2016, length=202752, window=hidenormalshowminimized
File size
3.3 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
654494946b2ca413be486cd51f6463e37f7622ea
SHA256
7b35f1dc42f6c7d3329403e2123537285abe2980f3e1142fc9a3ad4aa5213a27
MD5
5579f970a301d4cd762d7c0adab89be8

Signatures

Execution

T1204 suspicious_lnk: LNK file with suspicious content
T1059 suspicious_cmd_arguments: Cmd.exe uses file as a data source for the standard input stream

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object