Managed XDR

nf-2025-11-200800.pdf.lnk — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
nf-2025-11-200800.pdf.lnk
Тип файла
MS Windows shortcut, Item id list present, Points to a file or directory, Has Description string, Has Relative path, Has command line arguments, Icon number=11, Archive, ctime=Sat Sep 20 15:55:39 2025, mtime=Tue Oct 28 00:44:07 2025, atime=Sat Sep 20 15:55:39 2025, length=344064, window=hidenormalshowminimized
Размер файла
2.1 KB
Первое обнаружение
Последнее обнаружение

Окружение

w10/x64 en

Хеши

SHA1
c2cafbd1fa17f85124421cf45aa8162893d42f38
SHA256
075d7a837ebb3280e9cc9b6ef98dc290b750d35e793a6e19cb8c8842b7b7db1c
MD5
643e5c1ee5f03c1d10d6984b05d680ff

Сигнатуры

Execution

T1204 suspicious_lnk: LNK file with suspicious content
T1059.001 suspicious_powershell: Creates suspicious powershell process
T1059.001 suspicious_process: Spawns a suspicious process

Defense Evasion

T1497.003 antisandbox_idletime: Detects Windows Idle Time to determine the uptime

Discovery

T1497.003 antisandbox_idletime: Detects Windows Idle Time to determine the uptime

Other

creates_suspended_process: Creates suspended process
test_check_service: Starts services
yara_rules: Static rules