Managed XDR

thu-moi-chuong-trinh-s...su-kien-2025-.pdf-.lnk — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
thu-moi-chuong-trinh-su-kien-2025.pdf-thu-moi-chuong-trinh-su-kien-2025-.pdf-thu-moi-chuong-trinh-su-kien-2025-.pdf-thu-moi-chuong-trinh-su-kien-2025-.pdf-.lnk
Тип файла
MS Windows shortcut, Item id list present, Points to a file or directory, Has Working directory, Has command line arguments, Icon number=-1, Archive, ctime=Wed Jun 26 19:13:02 2013, mtime=Wed Jun 26 19:13:02 2013, atime=Wed Jun 26 19:13:02 2013, length=236032, window=hidenormalshowminimized
Размер файла
1.9 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x64 en

Хеши

SHA1
647961f213f28ed99e6d0d0313f0f0ccacc0691a
SHA256
da74fd5d06a9a333d45494a1492d6c9fea98fd9f9111e35dd9ad787b7235e92e
MD5
2ab723c311a55abced4ca6a82eb317bc

Сигнатуры

Execution

T1204 suspicious_lnk: LNK file with suspicious content

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1134 opens_process_token: Opens the access token associated with a process

Other

creates_exe: Creates executable files in the file system
executes_dropped_exe: Executes dropped exe files
unexpected_exception: Unexpected exception
no_graphical_activity: No graphic activity
creates_suspended_process: Creates suspended process
yara_rules: Static rules