MALICIOUS — photov_815344310912.lnk
MALICIOUS — photov_815344310912.lnk is a lnk sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100), attributed to the Sonbokli family. 2 of 51 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
3f52d85e4da57d749d0b30e1c4709871d3ddafe7ca3383b41404980ce46ce90b - SHA-1:
2d6fab5a07e23fa08421f4b39a580d1f30078109 - MD5:
c4ea233268d3976e82a6ba00f7321063 - ssdeep:
24:8oZw9EgWUcHOTRMMZYXn6kNqCUlVmOUiLjYYWmfN:8oZY6USO9MMZgnNNqCUyOjLjtWs - TLSH:
T1CC1487C2206C4B75D32080EC4A73E2AE48B5906A10FDA605EA16A47697034A3F5B3F76 - Submitted as: photov_815344310912.lnk
- File type: lnk · Size: 1897 bytes
- Verdict: malicious (94/100) · Family: Sonbokli
Detections (2 of 51 engines)
- Microsoft Defender: Trojan:Win32/Sonbokli.A!cl
- Kaspersky (KVRT): HEUR:Trojan.WinLNK.Agent.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 6 weighted signals:
- Memory forensics: 6 finding(s), e.g. RWX/private injected region in taskhostw.exe (pid 7224) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Microsoft Defender flagged Trojan:Win32/Sonbokli.A!cl (rule
Trojan:Win32/Sonbokli.A!cl) - engine signal, weight 0.55, confidence 0.85 - Shortcut launches: powershell - static signal, weight 0.50, confidence 0.80
- Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
18750 behavior events · 2 ATT&CK techniques · 13 dropped files.
Runtime network
- searchapp.bundleassets.example
- www.msftconnecttest.com
- staging.to-do.officeppe.com
- ycjlvalve.com
- www.bing.com
- desktop-hsgcbep
- config.edge.skype.com
- tas02.sls.update.microsoft.com
- dns.msftncsi.com
- to-do.microsoft.com
- settings-win.data.microsoft.com
- ctldl.windowsupdate.com
- staging.to-do.microsoft.com
- edge.microsoft.com
- teams.microsoft.com
- g.live.com
- aps.prod.windows.com
- self.events.data.microsoft.com
- ecs.office.com
- 192.168.122.106
Dropped files
- /opt/CAPEv2/storage/analyses/4473/files/96ad1146eb96877eab5942ae0736b82d8b5e2039a80d3d6932665c1a4c87dcf7 -
96ad1146eb96877eab5942ae0736b82d8b5e2039a80d3d6932665c1a4c87dcf7 - /opt/CAPEv2/storage/analyses/4473/files/2daf2f7680811e4a44b167f1c1f137e222321c3498367e9ddb49a771600c67dd -
2daf2f7680811e4a44b167f1c1f137e222321c3498367e9ddb49a771600c67dd - 8a7128ea0856d9389059a71e9cc44249aa54cb35cce1cba612ca91930ae09708 -
8a7128ea0856d9389059a71e9cc44249aa54cb35cce1cba612ca91930ae09708 - d05e31a5d6d84ce6e6f5a8a1047323c5c2e478f03b176e4ece5c455206eb40d7 -
d05e31a5d6d84ce6e6f5a8a1047323c5c2e478f03b176e4ece5c455206eb40d7 - cf23ddc66d314a76ffaf836fff6e8ff2e0a4a447d485534bff3e11023567d0f7 -
cf23ddc66d314a76ffaf836fff6e8ff2e0a4a447d485534bff3e11023567d0f7 - 95e2aa7d8d53f15ad5218de8455d362392b04ee3e91d486705460734317c4756 -
95e2aa7d8d53f15ad5218de8455d362392b04ee3e91d486705460734317c4756 - 3103f26ca27ea7adae6293c55190f26e1ed5f330c6a677499612dc8816eec5c4 -
3103f26ca27ea7adae6293c55190f26e1ed5f330c6a677499612dc8816eec5c4 - dde4332a2e8559e3d79ff3c697b218e8e04149dff087dfe0b54df0a5873c9027 -
dde4332a2e8559e3d79ff3c697b218e8e04149dff087dfe0b54df0a5873c9027 - 68e1f2c34ae10156385fae339869b441d80000d7b070311a9d9a84e521f22bbb -
68e1f2c34ae10156385fae339869b441d80000d7b070311a9d9a84e521f22bbb - 062349c0167ab4ca04b40fc477e0110b82e1c3c968160f31e29c9fcb849559cb -
062349c0167ab4ca04b40fc477e0110b82e1c3c968160f31e29c9fcb849559cb - 307dff45c771143c3d5848e936ed4575dc7fe908455b860a175aaf18d080588a -
307dff45c771143c3d5848e936ed4575dc7fe908455b860a175aaf18d080588a - ca508e279f5f10bac4ffc113b2ab7e907a4f29d787bd9844f1b98280ac9b198e -
ca508e279f5f10bac4ffc113b2ab7e907a4f29d787bd9844f1b98280ac9b198e - 6e10c215c6ed40289a33c7a5f532bd29728963a9b644b5ffaca920685e0da5f9 -
6e10c215c6ed40289a33c7a5f532bd29728963a9b644b5ffaca920685e0da5f9
Embedded domains
- staging.to-do.officeppe.com
- ycjlvalve.com
More Sonbokli samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report