Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | April 29, 2025, 4:21 p.m. | April 29, 2025, 4:23 p.m. |
-
cmd.exe "C:\Windows\System32\cmd.exe" /c start /wait "PBAB" C:\Users\test22\AppData\Local\Temp\Important_Document.pdf.lnk
2544-
cmd.exe "C:\WINDOWS\system32\cmd.exe" /c esentutl.exe /y "%cd%\Important_Document.pdf.lnk:PDF.pdf" /d "%cd%\Important_Document.pdf" /o & IF EXIST "%cd%\Important_Document.pdf" (start "" "%cd%\Important_Document.pdf" & del "%cd%\Important_Document.pdf.lnk") ELSE msg * "Cannot open file, please extract manually."
2660-
esentutl.exe esentutl.exe /y "C:\Windows\system32\Important_Document.pdf.lnk:PDF.pdf" /d "C:\Windows\system32\Important_Document.pdf" /o
2756
-
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
No hosts contacted. |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
file | C:\Users\test22\AppData\Local\Temp\Important_Document.pdf.lnk |
cmdline | "C:\WINDOWS\system32\cmd.exe" /c esentutl.exe /y "%cd%\Important_Document.pdf.lnk:PDF.pdf" /d "%cd%\Important_Document.pdf" /o & IF EXIST "%cd%\Important_Document.pdf" (start "" "%cd%\Important_Document.pdf" & del "%cd%\Important_Document.pdf.lnk") ELSE msg * "Cannot open file, please extract manually." |
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | DebuggerException__SetConsoleCtrl | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep |
cmdline | "C:\WINDOWS\system32\cmd.exe" /c esentutl.exe /y "%cd%\Important_Document.pdf.lnk:PDF.pdf" /d "%cd%\Important_Document.pdf" /o & IF EXIST "%cd%\Important_Document.pdf" (start "" "%cd%\Important_Document.pdf" & del "%cd%\Important_Document.pdf.lnk") ELSE msg * "Cannot open file, please extract manually." |
file | C:\Windows\System32\Important_Document.pdf.lnk:PDF.pdf |
CTX | lnk.trojan.generic |
Skyhigh | BehavesLike.Trojan.xx |
VIPRE | Heur.BZC.YAX.Pantera.69.4FB34A79 |
Arcabit | Heur.BZC.YAX.Pantera.69.4FB34A79 |
TrendMicro-HouseCall | HEUR_LNKEXEC.C |
BitDefender | Heur.BZC.YAX.Pantera.69.4FB34A79 |
MicroWorld-eScan | Heur.BZC.YAX.Pantera.69.4FB34A79 |
Emsisoft | Heur.BZC.YAX.Pantera.69.4FB34A79 (B) |
TrendMicro | HEUR_LNKEXEC.C |
Detected | |
Microsoft | Trojan:Script/Wacatac.B!ml |
GData | Heur.BZC.YAX.Pantera.69.4FB34A79 |
Varist | LNK/ABTrojan.BPDU- |
VBA32 | Trojan.Link.DoubleRun |
Ikarus | Win32.Outbreak |
Zoner | Probably Heur.LNKScript |