Managed XDR

normal.lnk — malware analysis report

File info

Filename
normal.lnk
File type
MS Windows shortcut, Item id list present, Has Description string, Has Relative path, Has Working directory, Has command line arguments, Icon number=70, ctime=Mon Jan 1 00:00:00 1601, mtime=Mon Jan 1 00:00:00 1601, atime=Mon Jan 1 00:00:00 1601, length=0, window=hidenormalshowminimized
File size
2 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
9bfe5173420ce46b5bdfc73c73f3e466e785e94d
SHA256
65763d2bf1ad08f85d2dd6561075dcd34d98b8a0032ac378d256b0bc1a006ed4
MD5
4d8ac03f663c52a170ef75ce33745d30

Signatures

Execution

T1204 suspicious_lnk: LNK file with suspicious content
T1059.001 suspicious_powershell: Creates suspicious powershell process
T1059.001 suspicious_process: Spawns a suspicious process

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1518 locates_browser: Attempts to identify where browsers are installed

Other

yara_rules: Static rules
creates_exe: Creates executable files in the file system
unexpected_exception: Unexpected exception
ps_ep_changed: Changes Powershell execution policy
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object