Managed XDR

lnk.eml — malware analysis report

File info

Filename
lnk.eml
File type
RFC 822 mail, ASCII text, with CRLF line terminators
File size
16.5 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
ab92f1a60533f9cc92e8f8a6ce3c65bff2b19b19
SHA256
2f3b70ec8d1f08e4523bddc0656fa269d8a83ea07fda9f5119bf690362107a20
MD5
4c160c3043cdbf8b4cd7b43fbc72da5c

Signatures

Execution

T1204 suspicious_lnk: LNK file with suspicious content
T1059.001 url_cmdline: Cmdline of process contains URL
T1059.003 url_cmdline: Cmdline of process contains URL

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object