Managed XDR

c-users-public-documen...la-write-111111111.lnk — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
c-users-public-documents-ngla-write-111111111.lnk
Тип файла
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has command line arguments, Icon number=23, Archive, ctime=Mon Jul 13 23:25:32 2009, mtime=Mon Jul 13 23:25:32 2009, atime=Tue Jul 14 01:39:31 2009, length=20480, window=hidenormalshowminimized
Размер файла
1.2 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x64 en

Хеши

SHA1
965adbef3d084c1826470fc34a36267ea479f37c
SHA256
347cf01f958df4a44c19902c2fc6b4ee124be41fdd5448e74768f3e276d795af
MD5
f3921993319d83d1b38519a7d11e677b

Сигнатуры

Execution

T1053.005 creates_tasks: Creates a delayed task using Task Scheduler
T1053.005 persistence_autorun: Makes itself run automatically on Windows startup

Persistence

T1053.005 creates_tasks: Creates a delayed task using Task Scheduler
T1053.005 persistence_autorun: Makes itself run automatically on Windows startup

Privilege Escalation

T1053.005 creates_tasks: Creates a delayed task using Task Scheduler
T1053.005 persistence_autorun: Makes itself run automatically on Windows startup

Defense Evasion

T1027.002 unnamed_memory_regions: Code was executed in unnamed regions

Other

unexpected_exception: Unexpected exception
no_graphical_activity: No graphic activity
creates_suspended_process: Creates suspended process
yara_rules: Static rules