Managed XDR

yt-stream-downloader.lnk — malware analysis report

File info

Filename
yt-stream-downloader.lnk
File type
MS Windows shortcut, Item id list present, Points to a file or directory, Has command line arguments, Icon number=122, Archive, ctime=Thu Apr 10 13:44:43 2025, mtime=Wed May 14 12:14:27 2025, atime=Thu Apr 10 13:44:43 2025, length=376832, window=hidenormalshowminimized
File size
1.5 KB
First seen
Last seen

Environment

win7/x64 en

Hashes

SHA1
b2ac659000bbbb9751f9e83688cf72b5843426bf
SHA256
d29910950318ecf938353b5b85e7f3d624313b7a960ed0c57cab5148f4076338
MD5
98843e3ca2c2bcfdf7eb5df1b2e36982

Signatures

Execution

T1204 suspicious_lnk: LNK file with suspicious content
T1047 has_wmi: Executes one or several WMI requests

Defense Evasion

T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1070.004 self_removal_command: Executes command to delete itself

Discovery

T1082 uses_windows_utilities: Uses Windows utilities for basic Windows functionality
T1518 locates_browser: Attempts to identify where browsers are installed
T1082 reads_csrss: Attempts to read csrss.exe memory

Other

unexpected_exception: Unexpected exception
no_graphical_activity: No graphic activity
creates_suspended_process: Creates suspended process
yara_rules: Static rules