Managed XDR

inv0055bacs.pdf.lnk — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
inv0055bacs.pdf.lnk
Тип файла
MS Windows shortcut, Item id list present, Has Working directory, Has command line arguments, Icon number=0, ctime=Mon Jul 7 11:03:04 2025, mtime=Mon Jul 7 11:03:04 2025, atime=Mon Jul 7 11:03:04 2025, length=0, window=hidenormalshowminimized
Размер файла
527 Bytes
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
71f041cd253d1a76780af8340036d014042772a8
SHA256
3ce8880daa4cfb3b40bed78c8fa3e303a73e8c1bc2c577d8afdbbf679dbd110e
MD5
41f88666d52fb7f01d1bb7eed02ed403

Сигнатуры

Execution

T1204 suspicious_lnk: LNK file with suspicious content

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.001 antivm_disk_size: Checks the amount of free disk space
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1083 crawls_directories: Opens a huge number of directories all over disk C: (possibly, searches for sensitive data)
T1497.001 antivm_disk_size: Checks the amount of free disk space
T1518 locates_browser: Attempts to identify where browsers are installed

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process