Managed XDR

shortcut.lnk (More_Eggs) — malware analysis report

File info

Filename
shortcut.lnk
File type
MS Windows shortcut, Item id list present, Has Description string, Has Relative path, Has Working directory, Has command line arguments, Icon number=70, Archive, ctime=Mon Jan 1 00:00:00 1601, mtime=Mon Jan 1 00:00:00 1601, atime=Mon Jan 1 00:00:00 1601, length=0, window=hide
File size
7.6 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
ef9eb4f2860f3d5f099240ec0081e1d5daefaef7
SHA256
34a5c7cda6f542de88a80249b11ed0fd72642381deae036754f420cb7e2c96d5
MD5
90b8f38015156ca45eb6362239e8cd9c

Malwares

  • More_Eggs

Signatures

Execution

T1204 suspicious_lnk: LNK file with suspicious content
T1059.001 suspicious_powershell: Creates suspicious powershell process
T1047 has_wmi: Executes one or several WMI requests
T1559.001 com_exec: Execution of Win32_Process.Create COM Method
T1059.001 url_cmdline: Cmdline of process contains URL
T1059.003 url_cmdline: Cmdline of process contains URL

Persistence

T1037 persistence_autorun: Makes itself run automatically on Windows startup

Privilege Escalation

T1037 persistence_autorun: Makes itself run automatically on Windows startup
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1218 wmic_create_process: Creates a process using wmic.exe utility
T1497 debugs_self: Creates a process and debugs it
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1070 stealth_window: A process created a hidden window

Credential Access

T1552 cookie_files: Accesses cookie files
T1555.003 cookie_files: Accesses cookie files

Discovery

T1497 debugs_self: Creates a process and debugs it
T1518.001 wmi_check_av: Uses WMI to check for installed antivirus software
T1057 has_wmi: Executes one or several WMI requests
T1518 locates_browser: Attempts to identify where browsers are installed
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1082 fingerprint_to_file: Collects data about system and user and writes it to a text file

Command and Control

T1071.001 network_http: Performs HTTP requests
T1071.001 wininet_https: Performs HTTP/HTTPS requests using WinInet

Other

yara_rules: Static rules
suspicious_process: Spawns a suspicious process
creates_exe: Creates executable files in the file system
executes_dropped_exe: Executes dropped exe files
unexpected_exception: Unexpected exception
no_graphical_activity: No graphic activity
create_rpc_bindings: Creates RPC connection
creates_suspended_process: Creates suspended process
break_limit_exceeded: Warning: function calls limit has been exceeded
get_policy_info: Retrieves information about a Policy object

Related reports