Managed XDR

raquele273320348683.lnk — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
raquele273320348683.lnk
Тип файла
MS Windows shortcut, Item id list present, Has Description string, Has command line arguments, Archive, ctime=*Invalid time*, mtime=*Invalid time*, atime=*Invalid time*, length=423201141, window=hidenormalshowminimized
Размер файла
17.5 KB
Первое обнаружение
Последнее обнаружение

Окружение

w10/x64 en

Хеши

SHA1
58c9693d71410518926fe192d2b1389ef4a42011
SHA256
4d344d744638acb8c16cb6829e17aea4a8f03963f73efad98885ce2ee0d6f405
MD5
c4d5d6d84dbd1243322ca9ed86964f6e

Сигнатуры

Resource Development

T1585.001 social_facebook: Connects to Facebook domains (potentially for information gathering)
T1586.001 social_facebook: Connects to Facebook domains (potentially for information gathering)

Execution

T1059 network_wscript_downloader: Wscript.exe initiated network communication
T1059.003 suspicious_cmd: Executes cmd.exe with a suspicious command line

Defense Evasion

T1027 suspicious_cmd: Executes cmd.exe with a suspicious command line
T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)

Discovery

T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)

Collection

T1560.001 archive_via_utility: Detected archiving data via utility

Command and Control

T1071 network_wscript_downloader: Wscript.exe initiated network communication
T1071.001 network_http: Performs HTTP requests
T1071.001 wininet_https: Performs HTTP/HTTPS requests using WinInet

Other

suricata_alert: Malicious traffic detected
creates_exe: Creates executable files in the file system
creates_suspended_process: Creates suspended process
message_box: Displays a message
test_check_service: Starts services