Managed XDR

thu-moi-chuong-trinh-s...su-kien-2025-.pdf-.lnk — malware analysis report

File info

Filename
thu-moi-chuong-trinh-su-kien-2025.pdf-thu-moi-chuong-trinh-su-kien-2025-.pdf-thu-moi-chuong-trinh-su-kien-2025-.pdf-thu-moi-chuong-trinh-su-kien-2025-.pdf-.lnk
File type
MS Windows shortcut, Item id list present, Points to a file or directory, Has Working directory, Has command line arguments, Icon number=-1, Archive, ctime=Wed Jun 26 19:13:02 2013, mtime=Wed Jun 26 19:13:02 2013, atime=Wed Jun 26 19:13:02 2013, length=236032, window=hidenormalshowminimized
File size
1.9 KB
First seen
Last seen

Environment

win7/x64 en

Hashes

SHA1
647961f213f28ed99e6d0d0313f0f0ccacc0691a
SHA256
da74fd5d06a9a333d45494a1492d6c9fea98fd9f9111e35dd9ad787b7235e92e
MD5
2ab723c311a55abced4ca6a82eb317bc

Signatures

Execution

T1204 suspicious_lnk: LNK file with suspicious content

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1134 opens_process_token: Opens the access token associated with a process

Other

creates_exe: Creates executable files in the file system
executes_dropped_exe: Executes dropped exe files
unexpected_exception: Unexpected exception
no_graphical_activity: No graphic activity
creates_suspended_process: Creates suspended process
yara_rules: Static rules