SUSPICIOUS — 3969e4862688697f863a136520f8b9eb298b28b20712a203bfa9f36832e4f591
SUSPICIOUS — 3969e4862688697f863a136520f8b9eb298b28b20712a203bfa9f36832e4f591 is a lnk sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (40/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
3969e4862688697f863a136520f8b9eb298b28b20712a203bfa9f36832e4f591 - SHA-1:
103c2596a87a1a9a68ddcef04c5b6eff03c1a5b7 - MD5:
3bddf789db2a1851f0312dd5e671371d - ssdeep:
24:8YfJtnyUD2+sibWCDN8l+Nh95hpvYQ3q/TpepTUkqddNXuHY:8aSwp/pP6/TpWTUrdLXuH - TLSH:
T1D51549CEDA1C4352C62D8879121BABEE5441709114A6B31C1C0C957A17F701FEFE556D - Submitted as: 3969e4862688697f863a136520f8b9eb298b28b20712a203bfa9f36832e4f591
- File type: lnk · Size: 2097 bytes
- Verdict: suspicious (40/100)
Detections (3 of 53 engines)
- Microsoft Defender: Trojan:Win32/WinLNK!rfn
- Emsisoft (Emergency Kit): Trojan.GenericKD.81021520
- Kaspersky (KVRT): HEUR:Trojan.WinLNK.Rufus.gen
Why this verdict
The suspicious score of 40/100 is the fusion of 1 weighted signal:
- Shortcut launches: embedded-url - static signal, weight 0.50, confidence 0.80
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report