Managed XDR

33.pdf.lnk — malware analysis report

File info

Filename
33.pdf.lnk
File type
MS Windows shortcut, Item id list present, Has Description string, Has Relative path, Has Working directory, Has command line arguments, Icon number=11, ctime=Mon Jan 1 00:00:00 1601, mtime=Mon Jan 1 00:00:00 1601, atime=Mon Jan 1 00:00:00 1601, length=0, window=hidenormalshowminimized
File size
2.4 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
d93f7cb6500f463c4d5ca52ac7e80190e8d6ab4d
SHA256
db72cd1b8af8b70fc77f9f82f75290502813ba5f53dd8a52afd17c5ccc83df77
MD5
5553b0344cf9e01c50b4540cfedcc863

Signatures

Execution

T1059.001 suspicious_powershell: Creates suspicious powershell process
T1059.001 suspicious_process: Spawns a suspicious process

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object