Managed XDR

sdchange.lnk — malware analysis report

File info

Filename
sdchange.lnk
File type
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Sat Apr 6 19:16:10 2024, mtime=Sat Apr 6 19:16:10 2024, atime=Sat Apr 6 19:16:10 2024, length=1254768, window=hide
File size
931 Bytes
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
66684a59c381c635de408a8c7603342b4b647d0f
SHA256
9f3a5099c24ebb8f3fb2e90439581aa259bea339f7a33c91e32f4629722c0612
MD5
75aa5d8dc4407b46de8a6878e66085bb

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object