Managed XDR

c-users-user-appdata-l...lio-portfolio.html.lnk — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
c-users-user-appdata-local-temp-dkpnbboz.j0g-portfolio-portfolio.html.lnk
Тип файла
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has command line arguments, Icon number=10, Archive, ctime=Sat Aug 30 08:34:39 2025, mtime=Sat Aug 30 08:34:39 2025, atime=Sat Aug 30 08:34:39 2025, length=376832, window=hidenormalshowminimized
Размер файла
15.2 KB
Первое обнаружение
Последнее обнаружение

Окружение

w10/x86 en

Хеши

SHA1
1e7dcfebcc15e224da921121d15c365a3d8f2832
SHA256
e7641ba7d9ad75fb6250975fc1f91c9024f9cba0c244dd616b01f92373e43efc
MD5
525f2cbd137ef34ccc1100ef732b3b92

Сигнатуры

Execution

T1204 suspicious_lnk: LNK file with suspicious content
T1059 powershell_cmd_longcommandline: Suspiciously long commandline

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1518 locates_browser: Attempts to identify where browsers are installed

Other

no_graphical_activity: No graphic activity
creates_suspended_process: Creates suspended process
writes_data: Writes big amount of data to disk
yara_rules: Static rules