Managed XDR

syarat-ketentuan-calon-pegawai.pdf.lnk — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
syarat-ketentuan-calon-pegawai.pdf.lnk
Тип файла
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=13, Archive, ctime=Sat Jun 22 15:10:43 2024, mtime=Sat Jun 22 19:38:31 2024, atime=Sat Jun 22 15:10:43 2024, length=323584, window=hidenormalshowminimized
Размер файла
9.6 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
5d7e0c9bed3d4350eaaa4c9be59f091da86d2a0c
SHA256
f5b18ebb9ef75341e1026302ccead411d6b7809279dd2bd27847d09330011ec3
MD5
27e6fdefe699b7053d7b024b0733b9f6

Сигнатуры

Execution

T1059.001 suspicious_powershell: Creates suspicious powershell process
T1204 suspicious_lnk: LNK file with suspicious content
T1059.003 suspicious_cmd: Executes cmd.exe with a suspicious command line

Persistence

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup

Privilege Escalation

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1036 copies_utilities: Copies and runs system utility with different name
T1027 suspicious_cmd: Executes cmd.exe with a suspicious command line
T1497.003 antisandbox_sleep_utilities: Uses Windows utilities for pausing the execution
T1497.001 antivm_network_adapters: Checks NIC addresses
T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 sets_privilegies_via_adjusttokenprivileges: Sets process privilege via AdjustTokenPrivileges
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.003 antisandbox_sleep_utilities: Uses Windows utilities for pausing the execution
T1497.001 antivm_network_adapters: Checks NIC addresses
T1518 locates_browser: Attempts to identify where browsers are installed
T1497.001 antivm_queries_computername: Retrieves the computer name

Command and Control

T1105 lolbin_extrac32: Download or Copy file with Extrac32
T1071.001 network_cnc_http: Suspicious HTTP traffic
T1071.001 network_http: Performs HTTP requests

Other

yara_rules: Static rules
creates_exe: Creates executable files in the file system
executes_dropped_exe: Executes dropped exe files
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object
checktokenmembership: Checks user token with CheckTokenMembership call
suricata_alert: Malicious traffic detected