SUSPICIOUS — Contrato_Indeniza_Brasil-43R37R.lnk
SUSPICIOUS — Contrato_Indeniza_Brasil-43R37R.lnk is a lnk sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (40/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
11697385efeae82dcabf246d4c4be611963bbeb75aad0fd0f8d8188bb2837b80 - SHA-1:
d9dc43fb22e77096ef1e7fce2b9fcaa2c20e7158 - MD5:
5c7eea3e7aebb92bbef2d01823c98b69 - ssdeep:
12:8rlfyOm/VnEXzQK9+a+UDaMyDjLaWwUlDFlIqubdpYrn1IlI7GXuHbLn1Il:8YPtneka+iM3LtjNqddNXuHY - TLSH:
T1B21326CF930C47A2CB2B8C3E060992BC6482B1D145D5791D2D0CE37F64E686BED91579 - Submitted as: Contrato_Indeniza_Brasil-43R37R.lnk
- File type: lnk · Size: 1511 bytes
- Verdict: suspicious (40/100)
Detections (2 of 53 engines)
- Microsoft Defender: Trojan:Win32/Ravartar!rfn
- Kaspersky (KVRT): HEUR:Trojan-Downloader.WinLNK.Agent.gen
Why this verdict
The suspicious score of 40/100 is the fusion of 1 weighted signal:
- Shortcut launches: mshta, embedded-url - static signal, weight 0.50, confidence 0.80
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report