Managed XDR

c-programdata-microsof...-96khz-native-bank.lnk — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
c-programdata-microsoft-windows-start-menu-programs-musiclab-realrick-6-download-and-install-96khz-native-bank.lnk
Тип файла
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has command line arguments, Archive, ctime=Fri Dec 11 02:49:16 2020, mtime=Mon Apr 21 22:31:01 2025, atime=Fri Aug 3 07:32:30 2018, length=60416, window=hide
Размер файла
969 Bytes
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
7e5f904f77c31c94cad06db9251368bd1143dbf2
SHA256
81e9ba5444850be3d2ad245e5e2d7570a51dcf53e8cd5b8e0da3ca36f0226deb
MD5
5ade973bda84f71a147ababdea898f8f

Сигнатуры

Execution

T1204 suspicious_lnk: LNK file with suspicious content
T1059.001 url_cmdline: Cmdline of process contains URL
T1059.003 url_cmdline: Cmdline of process contains URL

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1218 suspicious_cmdline: Executes a suspicious command
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Command and Control

T1071.001 network_http: Performs HTTP requests
T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp

Other

suspicious_process_network: Unusual process network activity detected
unexpected_exception: Unexpected exception
create_rpc_bindings: Creates RPC connection
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object
suricata_alert: Malicious traffic detected
yara_rules: Static rules