MALICIOUS — IMG_20260728_193826.jpg.lnk
MALICIOUS — IMG_20260728_193826.jpg.lnk is a lnk sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the Wacatac family. 3 of 51 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
c19dd67851c298feaf20fc3cb2b552fb204d209c35964ea4be49bb388d72f169 - SHA-1:
b1baa7bf86443e1e565620c9bbb60369f39b9aa3 - MD5:
b48fc476348ed3347616d258e13b5c02 - ssdeep:
24:8KSgdmGjMDvSwjKUaWU3AcPWkp+/CWKsE+YdKr4I0WK6c/6Cab7Oa7m:8KXmeKpUQCsPYQUIA6q6Cax - TLSH:
T18513AC8D526C9701CB7EDD21E9BDA47E9083396169B06D0D9C8F403E28E2517DDF0286 - Submitted as: IMG_20260728_193826.jpg.lnk
- File type: lnk · Size: 1395 bytes
- Verdict: malicious (98/100) · Family: Wacatac
Detections (3 of 51 engines)
- Microsoft Defender: Trojan:Script/Wacatac.B!ml
- Emsisoft (Emergency Kit): Trojan.Generic.40346813
- Kaspersky (KVRT): HEUR:Trojan.Multi.Powedon.a
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- Dropped a malicious payload (Wacatac): c19dd67851c298feaf20fc3cb2b552fb204d209c35964ea4be49bb388d72f169 - dynamic signal, weight 0.80, confidence 0.90
- Microsoft Defender flagged Trojan:Script/Wacatac.B!ml (rule
Trojan:Script/Wacatac.B!ml) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Generic.40346813 (rule
Trojan.Generic.40346813) - engine signal, weight 0.55, confidence 0.85 - Shortcut launches: powershell - static signal, weight 0.50, confidence 0.80
- Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
61025 behavior events · 2 ATT&CK techniques · 4 dropped files.
Runtime network
- none
Dropped files
- /opt/CAPEv2/storage/analyses/5741/files/c19dd67851c298feaf20fc3cb2b552fb204d209c35964ea4be49bb388d72f169 -
c19dd67851c298feaf20fc3cb2b552fb204d209c35964ea4be49bb388d72f169 - /opt/CAPEv2/storage/analyses/5741/files/cb5b57bdf44d7822bd72a985be3d6b535884dd4419d53b9efeb09a22a9694c43 -
cb5b57bdf44d7822bd72a985be3d6b535884dd4419d53b9efeb09a22a9694c43 - /opt/CAPEv2/storage/analyses/5741/files/bb8e04c155562be8fd71bec611ad6169ed5c1fe0aa4d56136a699a776fd051d3 -
bb8e04c155562be8fd71bec611ad6169ed5c1fe0aa4d56136a699a776fd051d3 - a86e097cc9b56b883fe4f30c449ae8f45bed448c6902812e333b8575c235a137 -
a86e097cc9b56b883fe4f30c449ae8f45bed448c6902812e333b8575c235a137
File paths
- C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
More Wacatac samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report