Managed XDR

c-recycle.bin-s-1-5-21...ch-window-switcher.lnk — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
c-recycle.bin-s-1-5-21-2728444500-1079535748-4130302051-500-rape061.user-appdata-roaming-microsoft-internet-explorer-quick-launch-window-switcher.lnk
Тип файла
MS Windows shortcut, Item id list present, Has Description string, Icon number=-258, ctime=Mon Jan 1 00:00:00 1601, mtime=Mon Jan 1 00:00:00 1601, atime=Mon Jan 1 00:00:00 1601, length=0, window=hide
Размер файла
224.3 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
f8de5cc6be32f0a7a5b4ab8d7fc4367de2d7a23f
SHA256
85c40a1adc49b64d02f121a3d764546ab3c2a90cb43cc6fda8a19b05dca3d24b
MD5
3bae22650a321ef2d750628558c20885

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
no_graphical_activity: No graphic activity
creates_suspended_process: Creates suspended process