Managed XDR

aqrfile.lnk-c1-pt233 — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
aqrfile.lnk-c1-pt233
Тип файла
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has command line arguments, Icon number=3, Archive, ctime=Tue Jun 26 09:53:50 2001, mtime=Thu Sep 29 19:45:23 2016, atime=Tue Jun 26 09:53:50 2001, length=118834, window=hide
Размер файла
549 Bytes
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
35f3a0841fd79436a1c6f7397fe94dead51d3dec
SHA256
70fb29e7ce5f180c882549bc4e661c16f137df8e3918041472ccc33e91ce3cb4
MD5
8b22e82ca8de87fdd39cc799fbd1d3a6

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
no_graphical_activity: No graphic activity
creates_suspended_process: Creates suspended process
message_box: Displays a message
get_policy_info: Retrieves information about a Policy object