MALICIOUS — photov_460772503095.lnk
MALICIOUS — photov_460772503095.lnk is a lnk sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the Sonbokli family. 2 of 51 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
74615e4b45a575a83edb00df35ed748d7532de7839fe9d064cb69a766842856d - SHA-1:
92501823f62fbe955d53468e5de11b7a26f6d738 - MD5:
912aa0e6170d7cdb4877ceafa5c99cb3 - ssdeep:
24:8oIQZcTsol/kG3fl0FnCjJsllluWtlSWnSXn6olml/3lvNqCUKW+VmO+LEcfW:8opGTpd+CjJHDTnWNqCUK8O+d+ - TLSH:
T1AB1499CD039C0E78C3291CAC9A70E39EC986D09419BD6907AD4ADD321323853D973972 - Submitted as: photov_460772503095.lnk
- File type: lnk · Size: 1724 bytes
- Verdict: malicious (98/100) · Family: Sonbokli
Detections (2 of 51 engines)
- Microsoft Defender: Trojan:Win32/Sonbokli.A!cl
- Kaspersky (KVRT): HEUR:Trojan.WinLNK.Agent.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 9 weighted signals:
- Memory forensics: 5 finding(s), e.g. RWX/private injected region in taskhostw.exe (pid 6612) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Microsoft Defender flagged Trojan:Win32/Sonbokli.A!cl (rule
Trojan:Win32/Sonbokli.A!cl) - engine signal, weight 0.55, confidence 0.85 - Shortcut launches: powershell - static signal, weight 0.50, confidence 0.80
- Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
18616 behavior events · 2 ATT&CK techniques · 13 dropped files.
Runtime network
- searchapp.bundleassets.example
- www.msftconnecttest.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- wolkamo.com
- www.bing.com
- desktop-hsgcbep
- aps.prod.windows.com
- tas02.sls.update.microsoft.com
- config.edge.skype.com
- to-do.microsoft.com
- settings-win.data.microsoft.com
- dns.msftncsi.com
- ctldl.windowsupdate.com
- staging.to-do.microsoft.com
- edge.microsoft.com
- watson.events.data.microsoft.com
- teams.microsoft.com
- g.live.com
- fs.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/4058/files/96ad1146eb96877eab5942ae0736b82d8b5e2039a80d3d6932665c1a4c87dcf7 -
96ad1146eb96877eab5942ae0736b82d8b5e2039a80d3d6932665c1a4c87dcf7 - /opt/CAPEv2/storage/analyses/4058/files/d6f21a103376552859861eeefd8312ac2fb1be41dd2a19e0f3666de666759327 -
d6f21a103376552859861eeefd8312ac2fb1be41dd2a19e0f3666de666759327 - e02fe10a1c494e785a8c7504ab9ecda320aa95ff58eba39d3eef3292fcc43f59 -
e02fe10a1c494e785a8c7504ab9ecda320aa95ff58eba39d3eef3292fcc43f59 - 1e915cd84f30cebcee7a00b5d3c55c9e50ffa7ae89354495de9df8e68c649b3a -
1e915cd84f30cebcee7a00b5d3c55c9e50ffa7ae89354495de9df8e68c649b3a - 64529bd28d6e2f3ed223773e8d0cb2b3974a2abf63bfdb16443ab61e6af78583 -
64529bd28d6e2f3ed223773e8d0cb2b3974a2abf63bfdb16443ab61e6af78583 - ce1dcf079117391703c48d740979726e67371525649ad9bc5d2bfeb8c2cdbcf5 -
ce1dcf079117391703c48d740979726e67371525649ad9bc5d2bfeb8c2cdbcf5 - efda27a2ef8f58ad8f925e933c925a3929beec63006b00ac7c23217e0838eed6 -
efda27a2ef8f58ad8f925e933c925a3929beec63006b00ac7c23217e0838eed6 - 53a12583654b3acad7ffb7f6f9cd62fac27aab99c842a6bb46c1dfff7871ab45 -
53a12583654b3acad7ffb7f6f9cd62fac27aab99c842a6bb46c1dfff7871ab45 - 6ea50ff4ed2d031836f5793307ace857d53d08b9ad3137197838174d414c05da -
6ea50ff4ed2d031836f5793307ace857d53d08b9ad3137197838174d414c05da - 90d5a4d722821cf489cadece12e94e3290f9af7d9c1689a538b2fe8d2474fa30 -
90d5a4d722821cf489cadece12e94e3290f9af7d9c1689a538b2fe8d2474fa30 - de508db780640bf56c46cb42cd1e05b3ba4f7907e83c02eb0392b393b8355377 -
de508db780640bf56c46cb42cd1e05b3ba4f7907e83c02eb0392b393b8355377 - 8e548a6e4f01e3c3149b0874cf391fd2387e62ff890c20f8be20a38f7a7d0702 -
8e548a6e4f01e3c3149b0874cf391fd2387e62ff890c20f8be20a38f7a7d0702 - b1555acdaf36ea9c5e211171b5a5c2b237fe40ac884812a98b1cff936fca40be -
b1555acdaf36ea9c5e211171b5a5c2b237fe40ac884812a98b1cff936fca40be
Embedded domains
- staging.to-do.officeppe.com
- wolkamo.com
More Sonbokli samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report