SUSPICIOUS — photov_541097563367.lnk
SUSPICIOUS — photov_541097563367.lnk is a lnk sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (68/100), attributed to the Sonbokli family. 2 of 51 detection engines flagged it.
Identification
- SHA-256:
456573dc3142f52dd2fc837cbfd26833bdc28005f935be82000b0983032b1bb5 - SHA-1:
392ff040197ae3a561b1d300392cab8070387c3b - MD5:
ba0b598f9b653c77876c8449f1e5c4b3 - ssdeep:
24:8otD1ezLqhxMTYkVkotyhKnXn6VXNqCUiVmO9hOd35Ah:8oL3MP2hCnMNqCUdOPOrAh - TLSH:
T1A81426CD32AC282BD73444ED5A31E6AE4A41606A04FEBB16921BE865C103853DD33BB4 - Submitted as: photov_541097563367.lnk
- File type: lnk · Size: 1807 bytes
- Verdict: suspicious (68/100) · Family: Sonbokli
Detections (2 of 51 engines)
- Microsoft Defender: Trojan:Win32/Sonbokli.A!cl
- Kaspersky (KVRT): HEUR:Trojan.WinLNK.Agent.gen
Why this verdict
The suspicious score of 68/100 is the fusion of 2 weighted signals:
- Microsoft Defender flagged Trojan:Win32/Sonbokli.A!cl (rule
Trojan:Win32/Sonbokli.A!cl) - engine signal, weight 0.55, confidence 0.85 - Shortcut launches: powershell - static signal, weight 0.50, confidence 0.80
Dynamic analysis (windows)
1 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
More Sonbokli samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report