Managed XDR

e7-ac-ac-e4-b8-89-e6-9...ae-ad-e7-8f-ad.pdf.lnk — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
e7-ac-ac-e4-b8-89-e6-9c-9f-e5-a4-aa-e5-b9-b3-e6-b4-8b-e5-b2-9b-e5-9b-bd-e5-a4-96-e4-ba-a4-e5-ae-98-e5-9f-b9-e8-ae-ad-e7-8f-ad.pdf.lnk
Тип файла
MS Windows shortcut, Item id list present, Points to a file or directory, Has command line arguments, Icon number=13, Archive, ctime=Wed Jun 26 05:21:48 2024, mtime=Thu Jul 18 12:00:02 2024, atime=Wed Jun 26 05:21:48 2024, length=867840, window=hideshowminimizedshowmaximized
Размер файла
2.8 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
7272568818a04b505c18b4e960240992f0d9668e
SHA256
03672dae225aa70a8983aa7d34785f66a35082f364dd1cb3815cd67049437ad7
MD5
30a33ecc7fa443bfe98aaa1f808e0ae4

Сигнатуры

Execution

T1204 suspicious_lnk: LNK file with suspicious content
T1059.001 url_cmdline: Cmdline of process contains URL
T1059.003 url_cmdline: Cmdline of process contains URL

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1218 suspicious_cmdline: Executes a suspicious command
T1126 disconnects_mapped_device: Removes network share connection
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1082 recon_systeminfo: Collects system information (ipconfig, netstat, systeminfo, net)

Other

unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object
yara_rules: Static rules