Managed XDR

2024-08-05_09-01-06_winscan_to_pdf.pdf.lnk — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
2024-08-05_09-01-06_winscan_to_pdf.pdf.lnk
Тип файла
MS Windows shortcut, Item id list present, Has Description string, Has Working directory, Has command line arguments, Icon number=13, ctime=Tue Aug 6 12:08:52 2024, mtime=Tue Aug 6 12:08:52 2024, atime=Tue Aug 6 12:08:52 2024, length=0, window=hidenormalshowminimized
Размер файла
935 Bytes
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
d956cdc066be3d5b6472c048b1888fe07d4588c2
SHA256
2cc62e6bdc66384585f03883f21087f4e8b315a749e31818781bd1169658babf
MD5
8f40d72c89542af3fd00d3795e9fbe74

Сигнатуры

Execution

T1204 suspicious_lnk: LNK file with suspicious content

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.001 antivm_disk_size: Checks the amount of free disk space
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antivm_disk_size: Checks the amount of free disk space

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
no_graphical_activity: No graphic activity
creates_suspended_process: Creates suspended process