Managed XDR

48991fec857ea520dac27cef4b216df8.virus — malware analysis report

File info

Filename
48991fec857ea520dac27cef4b216df8.virus
File type
MS Windows shortcut, Item id list present, Has command line arguments, Icon number=3, ctime=Mon Jan 1 00:00:00 1601, mtime=Mon Jan 1 00:00:00 1601, atime=Mon Jan 1 00:00:00 1601, length=0, window=hidenormalshowminimized
File size
900 Bytes
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
5f22a0cd420594fc65e9564f825df62dac227200
SHA256
9ca58153a347c8546c64ec5d74662b2842205f3ce5cd4bac1f76a56882d75234
MD5
48991fec857ea520dac27cef4b216df8

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object