MALICIOUS — photov_336948176123.lnk
MALICIOUS — photov_336948176123.lnk is a lnk sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100), attributed to the Ravartar family. 3 of 51 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
a788f4eac8fa3b79ebcb84142c03221fde097cd4a2325076a5cd09d282783757 - SHA-1:
6224c0cca72ec89f2070a355144d243b41089620 - MD5:
7b29fbfd31a4ac54ced124eaadca5466 - ssdeep:
48:8KBdJeMOOTYKK+O5znFB4kNqCUnImOqIb:8KrJeMWKKfzFB4h1nthG - TLSH:
T1AA1667CE536C0328C336C8B88633D5EE4C05F0A601B875268E15AC3995D6817DEF3AA0 - Submitted as: photov_336948176123.lnk
- File type: lnk · Size: 2668 bytes
- Verdict: malicious (94/100) · Family: Ravartar
Detections (3 of 51 engines)
- Microsoft Defender: Trojan:Win32/Ravartar!rfn
- Emsisoft (Emergency Kit): Trojan.Generic.40346853
- Kaspersky (KVRT): HEUR:Trojan.WinLNK.Agent.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 6 weighted signals:
- Microsoft Defender flagged Trojan:Win32/Ravartar!rfn (rule
Trojan:Win32/Ravartar!rfn) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Generic.40346853 (rule
Trojan.Generic.40346853) - engine signal, weight 0.55, confidence 0.85 - Shortcut launches: powershell - static signal, weight 0.50, confidence 0.80
- Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
24397 behavior events · 2 ATT&CK techniques · 8 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- searchapp.bundleassets.example
- icudon.com
- 192.168.122.109
- 224.0.0.252
- 192.168.122.255
- 192.168.122.1
- 192.168.122.111
- 192.168.122.110
- 192.168.122.112
- 239.255.255.250
- 192.168.122.106
Dropped files
- /opt/CAPEv2/storage/analyses/5909/files/96ad1146eb96877eab5942ae0736b82d8b5e2039a80d3d6932665c1a4c87dcf7 -
96ad1146eb96877eab5942ae0736b82d8b5e2039a80d3d6932665c1a4c87dcf7 - /opt/CAPEv2/storage/analyses/5909/files/c07771a13337c6fee57835c3dda7ffa8029928c3c54e6684207acf83bb85919b -
c07771a13337c6fee57835c3dda7ffa8029928c3c54e6684207acf83bb85919b - /opt/CAPEv2/storage/analyses/5909/files/fe59a5d839fdb3f3900579578b5f0b2d3d72fd420b9e366f4a15daa357e77b04 -
fe59a5d839fdb3f3900579578b5f0b2d3d72fd420b9e366f4a15daa357e77b04 - 8522004b7cca99fd3177795e9cfc224233e73697c635f6b10169bdadf8bb0968 -
8522004b7cca99fd3177795e9cfc224233e73697c635f6b10169bdadf8bb0968 - 5e96a692e356626a61dce4f6584346a910824ebf7118f0f7f6a8352c5e7fa54a -
5e96a692e356626a61dce4f6584346a910824ebf7118f0f7f6a8352c5e7fa54a - 6be378150bf23f5c31b04b971fee4c238bec86454d954e31b780cbbacdf9ed35 -
6be378150bf23f5c31b04b971fee4c238bec86454d954e31b780cbbacdf9ed35 - cdb12d0b7c4d55739930c4174d2a20228540f3edd20abb8fe21f8995ba47a147 -
cdb12d0b7c4d55739930c4174d2a20228540f3edd20abb8fe21f8995ba47a147 - adf1fd99d6d0e755a127bcdb1db521573ae35c2939f07808b3cef0d700eb9711 -
adf1fd99d6d0e755a127bcdb1db521573ae35c2939f07808b3cef0d700eb9711
Embedded domains
- inference.location.live.net
- icudon.com
More Ravartar samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report