MALICIOUS — IMG_20260727_073318.jpg.lnk
MALICIOUS — IMG_20260727_073318.jpg.lnk is a lnk sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100), attributed to the Phonzy family. 3 of 51 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
7f36af3651230837bf3198253501377e810198a92ace1a5a39bcbee64f828b04 - SHA-1:
967b27214d2b9602b6114effad5c4045934325b2 - MD5:
a96aeef4984e430c161c3672ff44c088 - ssdeep:
24:80LpdmGjMDvSwjKUaWU3AcPWkp+/CW1n3i+TXr4I0WK6c/6Cab7Oa7m:84jmeKpUQdnS+jUIA6q6Cax - TLSH:
T19B13AC8D566CA701CB7EDD21D8BD987E8083796269B47D095C8F403E18E201BDDF0286 - Submitted as: IMG_20260727_073318.jpg.lnk
- File type: lnk · Size: 1401 bytes
- Verdict: malicious (94/100) · Family: Phonzy
Detections (3 of 51 engines)
- Microsoft Defender: Trojan:Script/Phonzy.B!ml
- Emsisoft (Emergency Kit): Trojan.Generic.40342888
- Kaspersky (KVRT): HEUR:Trojan.Multi.Powedon.a
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 6 weighted signals:
- Microsoft Defender flagged Trojan:Script/Phonzy.B!ml (rule
Trojan:Script/Phonzy.B!ml) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Generic.40342888 (rule
Trojan.Generic.40342888) - engine signal, weight 0.55, confidence 0.85 - Shortcut launches: powershell - static signal, weight 0.50, confidence 0.80
- Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
28716 behavior events · 2 ATT&CK techniques · 3 dropped files.
Runtime network
- searchapp.bundleassets.example
- www.msftconnecttest.com
- desktop-hsgcbep
- www.bing.com
- config.edge.skype.com
- aefd.nelreports.net
- watson.events.data.microsoft.com
- g.live.com
- dns.msftncsi.com
- self.events.data.microsoft.com
- edge.microsoft.com
- www.msftncsi.com
- time.windows.com
- settings-win.data.microsoft.com
- licensing.mp.microsoft.com
- tsfe.trafficshaping.dsp.mp.microsoft.com
- geo.prod.do.dsp.mp.microsoft.com
- cp801.prod.do.dsp.mp.microsoft.com
- geover.prod.do.dsp.mp.microsoft.com
- 192.168.122.109
Dropped files
- /opt/CAPEv2/storage/analyses/5126/files/5bcdfb9471ad10f35c51e587c750c0019970c9642b76ce7d3f3b375a31378739 -
5bcdfb9471ad10f35c51e587c750c0019970c9642b76ce7d3f3b375a31378739 - 9968ccfbeeb7d5a14a8227fc5595f0314f3448b8ab9bfc2adcefde12b8b290c8 -
9968ccfbeeb7d5a14a8227fc5595f0314f3448b8ab9bfc2adcefde12b8b290c8 - 00542cc3f4b46b084adef65341f289afc98b718aee059b8372c07cf7ad06f144 -
00542cc3f4b46b084adef65341f289afc98b718aee059b8372c07cf7ad06f144
Embedded domains
- aefd.nelreports.net
File paths
- C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
More Phonzy samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report