Managed XDR

c-users-user-appdata-l...ocal-84556c-af202b.lnk — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
c-users-user-appdata-local-84556c-af202b.lnk
Тип файла
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Tue Jun 3 01:32:39 2025, mtime=Tue Jun 3 01:32:39 2025, atime=Tue Jun 3 01:32:39 2025, length=62, window=hidenormalshowminimized
Размер файла
882 Bytes
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
bf924e241e8913464e254ffce4e5ecc4962ca985
SHA256
430cccb3e26cfee250defae8ad80b8b84c9b1762fc428ae0a0e1a3ef75d2f058
MD5
ecb9cc265281ab57e634aa3b238107e0

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object