Managed XDR

c-users-user-appdata-l...9bh_curriculo_0910.lnk — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
c-users-user-appdata-local-temp-1bxu1laz.joz-curriculo_outubro_2024_vucdqlojiicv9bh_curriculo_0910.lnk
Тип файла
MS Windows shortcut, Item id list present, Has Relative path, Has command line arguments, Archive, ctime=Wed Oct 6 13:51:47 2021, mtime=Tue Oct 29 19:46:08 2024, atime=Wed Oct 6 13:51:47 2021, length=868864, window=hidenormalshowminimized
Размер файла
2 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
4971eea628f49eee5bbf58fedd3e9840f7c5fbc5
SHA256
300885f3867cf50160e6ba3838674acab04ef6a8c67065a9f8e3f0d5f3ee32d3
MD5
4e0a6c46cb26099e73cb70bee8f16128

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
create_rpc_bindings: Creates RPC connection
creates_suspended_process: Creates suspended process