Managed XDR

2024-05-22-eddc294fc85...5a21dab41c98781765.lnk — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
2024-05-22-eddc294fc8599c7fccde15ac5516eb8fdab161aafe83e15a21dab41c98781765.lnk
Тип файла
MS Windows shortcut, Item id list present, Has Description string, Has Relative path, Has command line arguments, Icon number=0, ctime=Mon Jan 1 00:00:00 1601, mtime=Mon Jan 1 00:00:00 1601, atime=Mon Jan 1 00:00:00 1601, length=0, window=hidenormalshowminimized
Размер файла
1.2 KB
Первое обнаружение
Последнее обнаружение

Окружение

w10/x64 en

Хеши

SHA1
80c817b04ae8a395d8f078bbf4e117895c13e6bd
SHA256
eddc294fc8599c7fccde15ac5516eb8fdab161aafe83e15a21dab41c98781765
MD5
27251cc401cfe955c65b5512b5684f8b

Сигнатуры

Execution

T1204 suspicious_lnk: LNK file with suspicious content
T1059.001 suspicious_process: Spawns a suspicious process
T1059.001 url_cmdline: Cmdline of process contains URL
T1059.003 url_cmdline: Cmdline of process contains URL

Defense Evasion

T1218 suspicious_cmdline: Executes a suspicious command

Command and Control

T1071.001 network_http: Performs HTTP requests
T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp
T1071.001 wininet_https: Performs HTTP/HTTPS requests using WinInet

Other

suspicious_process_network: Unusual process network activity detected
creates_suspended_process: Creates suspended process
test_check_service: Starts services
yara_rules: Static rules