Managed XDR

invoice.pdf.lnk — malware analysis report

File info

Filename
invoice.pdf.lnk
File type
MS Windows shortcut, Item id list present, Has Description string, Has Relative path, Has Working directory, Has command line arguments, Icon number=74, ctime=Fri Jan 3 15:45:42 2025, mtime=Fri Jan 3 15:45:42 2025, atime=Fri Jan 3 15:45:42 2025, length=0, window=hidenormalshowminimized
File size
684 Bytes
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
41062db8242db762895d32373a1d12c57bf1b259
SHA256
cdd25dfbbb768e7a47f800600a4dd9aa8488f0761d788817a207cfd2ccf37c28
MD5
7743bc22a7da3f5d0715375bc95b7003

Signatures

Execution

T1204 suspicious_lnk: LNK file with suspicious content
T1059.001 suspicious_process: Spawns a suspicious process
T1059.001 url_cmdline: Cmdline of process contains URL
T1059.003 url_cmdline: Cmdline of process contains URL

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1218 suspicious_cmdline: Executes a suspicious command
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files

Command and Control

T1071.001 wininet_https: Performs HTTP/HTTPS requests using WinInet

Other

suspicious_process_network: Unusual process network activity detected
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object
yara_rules: Static rules