Managed XDR

rosatom_between_paec-ses-dte.pdf.lnk — malware analysis report

File info

Filename
rosatom_between_paec-ses-dte.pdf.lnk
File type
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has command line arguments, Icon number=13, Archive, ctime=Tue Jul 30 11:20:08 2024, mtime=Wed Aug 21 06:19:48 2024, atime=Tue Jul 30 11:20:08 2024, length=289792, window=hidenormalshowminimized
File size
1.5 MB
First seen
Last seen

Environment

win7/x64 en

Hashes

SHA1
caeedc59285dc61de9d2b668d941a698d6dd4fe5
SHA256
59d648425b5e5797c3b50f49f033622bdb2ed0196e5562251966abf5bbc377a7
MD5
762c5e65af3563dd025c35c9614dbcb7

Signatures

Execution

T1204 suspicious_lnk: LNK file with suspicious content
T1059 suspicious_cmd_arguments: Cmd.exe uses file as a data source for the standard input stream

Defense Evasion

T1027.002 unnamed_memory_regions: Code was executed in unnamed regions

Other

unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process