Managed XDR

c-users-user-appdata-l...glisch-lerngalaxie.lnk — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
c-users-user-appdata-local-temp-1sorjhxe.oim-l-sungen-englisch-lerngalaxie.lnk
Тип файла
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Archive, ctime=Wed Feb 12 19:26:47 2025, mtime=Tue Mar 25 10:15:27 2025, atime=Wed Feb 12 19:26:47 2025, length=323584, window=hide
Размер файла
1.4 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
1eec5fad51a16c24891050f652c792724f347daf
SHA256
91496ead564a7b572a2aa7fe32e948b09b4c18a48f4dafb64fefc9bc54570823
MD5
c06334d5a67b5b4f9196738588a1b288

Сигнатуры

Execution

T1204 suspicious_lnk: LNK file with suspicious content

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

creates_many_processes: Spawns a lot of processes (over 70)
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
break_limit_exceeded: Warning: function calls limit has been exceeded
access_recyclebin: Manipulation with recyclebin detected
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
yara_rules: Static rules