Managed XDR

c-users-user-appdata-l...sylwl.nam-calendar.lnk — malware analysis report

File info

Filename
c-users-user-appdata-local-temp-rr4sylwl.nam-calendar.lnk
File type
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has command line arguments, Icon number=3, Archive, ctime=Sat Apr 6 02:18:38 2024, mtime=Tue Aug 6 08:38:10 2024, atime=Sat Apr 6 02:18:38 2024, length=946176, window=hidenormalshowminimized
File size
2.8 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
633965d7ce92ea189e36e5d32e4a1fbc12e60fd6
SHA256
3befc95fb07cf41c583042892aeb0b4c4af97afcfbfdd0fa1bf9467124e9ebf3
MD5
b86a724aaf89a0616547efe38feac918

Signatures

Execution

T1204 suspicious_lnk: LNK file with suspicious content
T1059.001 url_cmdline: Cmdline of process contains URL
T1059.003 url_cmdline: Cmdline of process contains URL

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
create_process_failed: Could not start the process
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object