Managed XDR
Group-IB MDP Report
File info
Filename: scratch-zoo-2025-05-09-eb9e33d33e00faf5f7f3c2911e16e9b0
File Type: MS Windows shortcut, Item id list present, ctime=Sat Jul 13 13:22:36 2013, mtime=Sat Jul 13 13:22:36 2013, atime=Sat Jul 13 13:22:36 2013, length=0, window=hide
File Size: 1 KB
Env info
win7/x86 en
Hashes
SHA1: b46b4d6e18c4bfb5bcd161a4552bb72bf1ffb9b9
SHA256: a6b2b03b3decbe3bbcf58d9a73716a6134857c8fd1ade8ead63bfde56ce2d700
MD5: eb9e33d33e00faf5f7f3c2911e16e9b0
Signatures
Privilege Escalation
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
Defense Evasion
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
Other
yara_rules: Static rules
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
Managed XDR