Managed XDR

l96771e37d8c9c2676c3d4722c75b67.lnk — malware analysis report

File info

Filename
l96771e37d8c9c2676c3d4722c75b67.lnk
File type
MS Windows shortcut, Item id list present, Has Description string, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, ctime=Mon Jan 1 00:00:00 1601, mtime=Mon Jan 1 00:00:00 1601, atime=Mon Jan 1 00:00:00 1601, length=0, window=hide
File size
8.1 KB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
d1626adf09620cc23467545aae1ce9c9decc154b
SHA256
553c0908974d457d1c97fe7a64f253b8e8f5dd8c738ee590d30d93526d2180ce
MD5
e8228a6705c3b2fcb31e1dda59d370b3

Signatures

Execution

T1059.001 suspicious_powershell: Creates suspicious powershell process
T1059.001 suspicious_process: Spawns a suspicious process
T1106 susp_callbacks: Suspicious usage of some WinAPI with callbacks

Persistence

T1037 persistence_autorun: Makes itself run automatically on Windows startup
T1574 dropper_dll: Creates DLL, which is then loaded into the process

Privilege Escalation

T1037 persistence_autorun: Makes itself run automatically on Windows startup
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1574 dropper_dll: Creates DLL, which is then loaded into the process

Defense Evasion

T1027.002 unnamed_memory_regions_contains_pe: One or several unnamed memory regions are PE files
T1497.003 antisandbox_idletime: Detects Windows Idle Time to determine the uptime
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1070 stealth_window: A process created a hidden window

Discovery

T1497.003 antisandbox_idletime: Detects Windows Idle Time to determine the uptime
T1518 locates_browser: Attempts to identify where browsers are installed

Command and Control

T1071.001 network_http: Performs HTTP requests

Other

creates_exe: Creates executable files in the file system
network_powershell: Powershell process network connection detected
no_graphical_activity: No graphic activity
creates_suspended_process: Creates suspended process
test_check_service: Starts services
suricata_alert: Malicious traffic detected
yara_rules: Static rules