Managed XDR

proposal.lnk — malware analysis report

File info

Filename
proposal.lnk
File type
MS Windows shortcut, Item id list present, Has Description string, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, ctime=Thu Jan 2 13:40:40 2025, mtime=Thu Jan 2 13:40:40 2025, atime=Thu Jan 2 13:40:40 2025, length=0, window=hidenormalshowminimized
File size
334.5 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
7a321fb59d280d19e42e4e4c266a0f466da15a24
SHA256
2c60d60f2145735f5ab0e082c38d28401db7d57ccf69970a04dd92aa0fd4a472
MD5
81e0e395446df8633e5c0601ff318773

Signatures

Execution

T1204 suspicious_lnk: LNK file with suspicious content

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.001 antivm_queries_computername: Retrieves the computer name
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antivm_queries_computername: Retrieves the computer name
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1135 server_share_info: Retrieves information about each shared resource on a server

Other

yara_rules: Static rules
creates_exe: Creates executable files in the file system
unexpected_exception: Unexpected exception
create_rpc_bindings: Creates RPC connection
creates_suspended_process: Creates suspended process
test_check_service: Starts services