MALICIOUS — photov_145078426722.lnk
MALICIOUS — photov_145078426722.lnk is a lnk sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100), attributed to the Sonbokli family. 3 of 51 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
e650419ef0a45a36a56bed92aecd5fc2491ba3aa131b888191804fc11ee9ec44 - SHA-1:
140ecceb453a50072d8228b3c4b85ddba0fa6d95 - MD5:
7ee9115b218223cbf03bd06ee3887953 - ssdeep:
24:8ohyj6Nw/Fkrv11nbVQltFtFVWaBXn6pWFkmsNqCUVVmOL/Uz0Yd:8oAj6S+ZwftXbhnZiNqCUiO0L - TLSH:
T12D147DC6523C2F2AC324E68CA63593BD4AC5506515FEAC428613F4318002BD3CEF38B9 - Submitted as: photov_145078426722.lnk
- File type: lnk · Size: 1786 bytes
- Verdict: malicious (96/100) · Family: Sonbokli
Detections (3 of 51 engines)
- Microsoft Defender: Trojan:Win32/Sonbokli.A!cl
- Emsisoft (Emergency Kit): Trojan.GenericKD.80985926
- Kaspersky (KVRT): HEUR:Trojan.WinLNK.Agent.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 7 weighted signals:
- Memory forensics: 3 finding(s), e.g. RWX/private injected region in powershell.exe (pid 1348) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Microsoft Defender flagged Trojan:Win32/Sonbokli.A!cl (rule
Trojan:Win32/Sonbokli.A!cl) - engine signal, weight 0.55, confidence 0.85 - Shortcut launches: powershell - static signal, weight 0.50, confidence 0.80
- Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 37 external host(s) at runtime (7 HTTP) - network signal, weight 0.40, confidence 0.80
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
16639 behavior events · 2 ATT&CK techniques · 7 dropped files.
Runtime network
- searchapp.bundleassets.example
- outlook.office365.com
- www.msftconnecttest.com
- outlook.cloud.microsoft
- wolkamo.com
- _dosvc._tcp.local
- login.live.com
- ctldl.windowsupdate.com
- ocsp.digicert.com
- settings-win.data.microsoft.com
- v10.events.data.microsoft.com
- time.windows.com
- desktop-hsgcbep._dosvc._tcp.local
- desktop-hsgcbep
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 1.0.240.10.in-addr.arpa
- 232.188.215.172.in-addr.arpa
Dropped files
- /opt/CAPEv2/storage/analyses/4580/files/96ad1146eb96877eab5942ae0736b82d8b5e2039a80d3d6932665c1a4c87dcf7 -
96ad1146eb96877eab5942ae0736b82d8b5e2039a80d3d6932665c1a4c87dcf7 - /opt/CAPEv2/storage/analyses/4580/files/dbe38dfb100bf58ef61997b2760453c809c35e0c779588a16a77d42af2576c9d -
dbe38dfb100bf58ef61997b2760453c809c35e0c779588a16a77d42af2576c9d - a4d099243a1424ef8b7161014c8f1c1107e0fdcc48a259df8818a74c8256a926 -
a4d099243a1424ef8b7161014c8f1c1107e0fdcc48a259df8818a74c8256a926 - 3b06956e58220dd49b49dbbe1c8b7bf43f14a653043fa0ecf2cf3b4ea5c7caf6 -
3b06956e58220dd49b49dbbe1c8b7bf43f14a653043fa0ecf2cf3b4ea5c7caf6 - c249ec4c7839432f4586609aa62b40839529cb1466c5f5e334caa5e342a596b7 -
c249ec4c7839432f4586609aa62b40839529cb1466c5f5e334caa5e342a596b7 - 53b0b6cb628f8b70cc6b830e3636efee71dd43c8f95948a91438d40d4560d7c2 -
53b0b6cb628f8b70cc6b830e3636efee71dd43c8f95948a91438d40d4560d7c2 - 5a27be40daae58f0d4736aa55bb0803ada17ee5a9af1b23cb25ca3afd55ae2e3 -
5a27be40daae58f0d4736aa55bb0803ada17ee5a9af1b23cb25ca3afd55ae2e3
Embedded domains
- wolkamo.com
Embedded IP addresses
- 20.190.167.19
- 23.40.52.209
- 4.247.188.224
- 20.184.175.9
- 203.26.79.13
- 172.215.188.232
- 74.178.76.128
- 20.42.179.192
- 52.148.114.188
- 20.184.175.4
- 57.154.63.210
- 52.168.117.175
- 20.190.167.20
- 92.223.78.30
- 2.18.225.206
- 2.18.226.34
- 23.214.54.132
- 20.184.175.23
- 20.42.73.31
- 23.11.36.157
- 23.221.133.182
- 23.40.52.111
- 74.179.71.159
- 135.233.95.80
- 72.145.35.116
More Sonbokli samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report