Managed XDR

1633bc81f948c3c70c6a029940d032a5.virus — malware analysis report

File info

Filename
1633bc81f948c3c70c6a029940d032a5.virus
File type
MS Windows shortcut, Item id list present, Points to a file or directory, Has command line arguments, Icon number=7, Archive, ctime=Sat Feb 1 16:49:04 2020, mtime=Sat Feb 1 16:49:04 2020, atime=Fri Mar 25 17:49:03 2016, length=345088, window=hidenormalshowminimized
File size
1.6 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
f1d52fe2c78fbd8ff4c629e5f41cd81ede8bfb4b
SHA256
b2f5968f2b1ce15ae9cddca3845a20de0331ee499b484198caccb28b13772907
MD5
1633bc81f948c3c70c6a029940d032a5

Signatures

Execution

T1204 suspicious_lnk: LNK file with suspicious content

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object