Managed XDR

2024-05-22-eddc294fc85...5a21dab41c98781765.lnk — malware analysis report

File info

Filename
2024-05-22-eddc294fc8599c7fccde15ac5516eb8fdab161aafe83e15a21dab41c98781765.lnk
File type
MS Windows shortcut, Item id list present, Has Description string, Has Relative path, Has command line arguments, Icon number=0, ctime=Mon Jan 1 00:00:00 1601, mtime=Mon Jan 1 00:00:00 1601, atime=Mon Jan 1 00:00:00 1601, length=0, window=hidenormalshowminimized
File size
1.2 KB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
80c817b04ae8a395d8f078bbf4e117895c13e6bd
SHA256
eddc294fc8599c7fccde15ac5516eb8fdab161aafe83e15a21dab41c98781765
MD5
27251cc401cfe955c65b5512b5684f8b

Signatures

Execution

T1204 suspicious_lnk: LNK file with suspicious content
T1059.001 suspicious_process: Spawns a suspicious process
T1059.001 url_cmdline: Cmdline of process contains URL
T1059.003 url_cmdline: Cmdline of process contains URL

Defense Evasion

T1218 suspicious_cmdline: Executes a suspicious command

Command and Control

T1071.001 network_http: Performs HTTP requests
T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp
T1071.001 wininet_https: Performs HTTP/HTTPS requests using WinInet

Other

suspicious_process_network: Unusual process network activity detected
creates_suspended_process: Creates suspended process
test_check_service: Starts services
yara_rules: Static rules