SUSPICIOUS — photov_457828597195.lnk
SUSPICIOUS — photov_457828597195.lnk is a lnk sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (68/100), attributed to the Sonbokli family. 3 of 51 detection engines flagged it.
Identification
- SHA-256:
055d7d5909ab7d89c05dd1d5fe031d05da505f347b8e8fbd174c2221317e73d6 - SHA-1:
7045def7b7d6c21fc9f0dbd86b0b760b5c6b4ac3 - MD5:
d520f7d93772f811a9c8766b5c60c896 - ssdeep:
24:8o7d6GV+Yxl6tyxo1Vh1LXn6VTSXNqCU8eUoVmOOWWca/GH:8o76PM2n3NqCUuOOpcaK - TLSH:
T131146ACA11F8192FD32494E845B3219EC992A0DF45BDB607E22698312182D03D8B3F97 - Submitted as: photov_457828597195.lnk
- File type: lnk · Size: 1887 bytes
- Verdict: suspicious (68/100) · Family: Sonbokli
Detections (3 of 51 engines)
- Microsoft Defender: Trojan:Win32/Sonbokli.A!cl
- Emsisoft (Emergency Kit): Trojan.GenericKD.80977779
- Kaspersky (KVRT): HEUR:Trojan.WinLNK.Agent.gen
Why this verdict
The suspicious score of 68/100 is the fusion of 2 weighted signals:
- Microsoft Defender flagged Trojan:Win32/Sonbokli.A!cl (rule
Trojan:Win32/Sonbokli.A!cl) - engine signal, weight 0.55, confidence 0.85 - Shortcut launches: powershell - static signal, weight 0.50, confidence 0.80
Dynamic analysis (windows)
1 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
More Sonbokli samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report