Managed XDR

camscanner_191027.lnk — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
camscanner_191027.lnk
Тип файла
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Wed Jul 9 07:00:15 2025, mtime=Mon Oct 13 07:01:00 2025, atime=Wed Jul 9 07:00:15 2025, length=455680, window=hidenormalshowminimized
Размер файла
2.1 KB
Первое обнаружение
Последнее обнаружение

Окружение

w10/x86 en

Хеши

SHA1
ced3bed0251aae0f47d6e4f7918ba307c8288858
SHA256
60a57ea4338a04327fd8eb73e12b73e8c052531fcae36bc317c4209e3129fd7d
MD5
be974c829471b209ec3fa7594fee29e7

Сигнатуры

Execution

T1204 suspicious_lnk: LNK file with suspicious content
T1059.001 suspicious_powershell: Creates suspicious powershell process
T1059.001 suspicious_process: Spawns a suspicious process

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1552.001 infostealer_bitcoin: Attempts to obtain access to Bitcoin/ALTCoin wallets
T1552 infostealer_mail: Collects personal data from local email clients

Discovery

T1083 crawls_directories: Opens a huge number of directories all over disk C: (possibly, searches for sensitive data)
T1518 locates_browser: Attempts to identify where browsers are installed

Collection

T1114 infostealer_mail: Collects personal data from local email clients

Other

no_graphical_activity: No graphic activity
creates_suspended_process: Creates suspended process
writes_data: Writes big amount of data to disk
yara_rules: Static rules
Managed XDR