Managed XDR

2.lnk — malware analysis report

File info

Filename
2.lnk
File type
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Wed May 15 03:26:38 2024, mtime=Mon Aug 26 08:33:27 2024, atime=Wed May 15 03:26:38 2024, length=576512, window=hide
File size
2.2 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
179403d08cd865d73d813bcf28bec2fcbd2c8ef8
SHA256
736e0a0f81ee7bfd2e03bb490f699e73ff0c898170faa16a7cbf541fd20ceb56
MD5
eb0ab08f2b5392c12ba65750f95bb1b4

Signatures

Execution

T1047 has_wmi: Executes one or several WMI requests

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1220 wmic_xls: Uses WMIC to execute a script
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files

Discovery

T1057 has_wmi: Executes one or several WMI requests
T1518 locates_browser: Attempts to identify where browsers are installed
T1082 reads_csrss: Attempts to read csrss.exe memory

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object