Managed XDR

cmd.lnk — malware analysis report

File info

Filename
cmd.lnk
File type
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Archive, ctime=Wed Nov 13 09:38:07 2024, mtime=Sun Dec 1 15:07:37 2024, atime=Wed Nov 13 09:38:07 2024, length=323584, window=hide
File size
1.5 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
b6784e13673bec7876794bc4f5c00ab6cba440c0
SHA256
555c061f21ff15968be5ce08f2cac34b628d889bf03a67cf17faa6f4ce7ddfda
MD5
5101acc89bf467f13afef0c367e1ecd7

Signatures

Execution

T1204 suspicious_lnk: LNK file with suspicious content

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.003 antisandbox_sleep_utilities: Uses Windows utilities for pausing the execution
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.003 antisandbox_sleep_utilities: Uses Windows utilities for pausing the execution

Other

creates_many_processes: Spawns a lot of processes (over 70)
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object