Managed XDR

prilozhenie_no.-1.doc.lnk — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
prilozhenie_no.-1.doc.lnk
Тип файла
MS Windows shortcut, Item id list present, Has Relative path, Has command line arguments, Icon number=0, ctime=Mon Jan 1 00:00:00 1601, mtime=Mon Jan 1 00:00:00 1601, atime=Mon Jan 1 00:00:00 1601, length=0, window=hide
Размер файла
2 MB
Первое обнаружение
Последнее обнаружение

Окружение

w10/x64 en

Хеши

SHA1
c310e4752a7f52d1ea32eb23fd9d35cb33e1272a
SHA256
03446e7dc87a01a5eac65bc3d82b02a488393cd2d6bd213ab3d90ffca25d6456
MD5
8ba399688dff40d189bf67653a54dc43

Сигнатуры

Execution

T1059.001 suspicious_powershell: Creates suspicious powershell process
T1059.001 suspicious_process: Spawns a suspicious process

Credential Access

T1552.001 infostealer_bitcoin: Attempts to obtain access to Bitcoin/ALTCoin wallets

Discovery

T1083 crawls_directories: Opens a huge number of directories all over disk C: (possibly, searches for sensitive data)
T1518 locates_browser: Attempts to identify where browsers are installed

Other

creates_exe: Creates executable files in the file system
no_graphical_activity: No graphic activity
creates_suspended_process: Creates suspended process
test_check_service: Starts services
yara_rules: Static rules