Managed XDR

03aa9ce2ae04469.lnk — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
03aa9ce2ae04469.lnk
Тип файла
MS Windows shortcut, Item id list present, Has Relative path, Has Working directory, Has command line arguments, Archive, ctime=Mon Jan 1 00:00:00 1601, mtime=Mon Jan 1 00:00:00 1601, atime=Mon Jan 1 00:00:00 1601, length=0, window=hidenormalshowminimized
Размер файла
1.3 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
13258f3c31b147b69c462373d7481b95f2a27d18
SHA256
d9fef1892ffaddc0efc1c4e20c6612935bf613896a07d25d700b4740f48473d3
MD5
efad546b6c76e836e7b43eec5e8f43fa

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object