Managed XDR

crypted_lnk.lnk — malware analysis report

File info

Filename
crypted_lnk.lnk
File type
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has command line arguments, Icon number=13, Archive, ctime=Sun Nov 19 09:20:35 2023, mtime=Sun Sep 1 02:15:01 2024, atime=Sun Nov 19 09:20:35 2023, length=289792, window=hidenormalshowminimized
File size
2.1 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
44074c72502293b2caa631ad892fc4a6c2d236a9
SHA256
e0bdfc4a589de5c0bf5f49c98f9a25d9694e643d7903ee7ba5de38777ffbd68b
MD5
f8fb0b799adc1e67886e4d44dae715ed

Signatures

Execution

T1204 suspicious_lnk: LNK file with suspicious content
T1059.003 executes_dropped_cmd: Executes dropped batch files

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1140 unpacking_utilities: Uses Windows utilities to unpack data
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1518 locates_browser: Attempts to identify where browsers are installed

Other

yara_rules: Static rules
creates_in_windows: Creates files in the Windows directory
creates_exe: Creates executable files in the file system
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object
checktokenmembership: Checks user token with CheckTokenMembership call